StudyToCert

All certifications / CC / Cheat sheet

CC 2026 outline cheat sheet

Every exam tip and key term from the free CC lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Security principles (24%)

Exam tips

Key terms

Confidentiality
Keeping information from being disclosed to unauthorized people, processes or devices.
Integrity
Assurance that data and systems are accurate, complete and changed only in authorized ways.
Availability
Timely and reliable access to information and systems for authorized users.
Sensitivity
A measure of how much harm would result from unauthorized disclosure of information.
DAD triad
Disclosure, alteration and destruction or denial: the attacker-side opposites of confidentiality, integrity and availability.
Authentication
Verifying that a claimed identity is genuine, for example with a password, token or biometric.
Authorization
Deciding what an authenticated identity is permitted to access or do.
Accounting
Recording the actions of authenticated users so they can be reviewed and traced; also called auditing.
Non-repudiation
Assurance that someone cannot credibly deny having performed an action, commonly provided by digital signatures and reliable logs.
Privacy
An individual's right to control the collection, use and sharing of information about them.
PII
Personally identifiable information: data that can identify a specific individual.
Knowledge factor
Something you know, such as a password or PIN.
Possession factor
Something you have, such as a smart card, hardware key or authenticator app.
Inherence factor
Something you are, meaning a biometric trait such as a fingerprint or face.
Multi-factor authentication (MFA)
Authentication that requires evidence from two or more different factor types.
False acceptance rate
How often a biometric system accepts an impostor; also called a Type II error.
Crossover error rate
The point where false acceptance and false rejection rates are equal, used to compare biometric systems.
Asset
Anything of value to an organization that needs protection, such as data, systems, people or reputation.
Threat
Any potential cause of harm to an asset, whether human, natural or technical.
Vulnerability
A weakness that a threat could exploit.
Likelihood
The probability that a threat will exploit a vulnerability in a given period.
Impact
The magnitude of harm that would result if a risk were realized.
Risk register
A document listing identified risks with their details, owners and treatments.
Qualitative assessment
Rating risks with descriptive scales such as low, medium and high, based on judgment.
Quantitative assessment
Rating risks in monetary terms using values such as SLE, ARO and ALE.
Annualized loss expectancy (ALE)
Expected yearly loss from a risk, calculated as SLE multiplied by ARO.
Risk transference
Shifting the financial impact of a risk to another party, for example through insurance.
Residual risk
The risk that remains after controls have been applied.
Administrative control
A policy, procedure or practice that directs people's behavior, such as training or background checks.
Technical control
A control implemented in hardware or software, such as a firewall or encryption.
Physical control
A control that protects facilities and equipment, such as locks, fences or guards.
Preventive control
A control that stops an incident from occurring.
Detective control
A control that identifies an incident during or after its occurrence.
Compensating control
An alternative control used when the primary control cannot be implemented.
Preamble
The introduction to the ISC2 Code of Ethics stating that members must adhere, and be seen to adhere, to the highest ethical standards as a condition of certification.
Canon
One of the four core principles of the ISC2 Code of Ethics, listed in priority order.
Principal
The employer, client or other party a professional serves.
Ethics complaint
A formal report to ISC2 alleging that a member violated the Code of Ethics.
Data poisoning
Deliberately corrupting a model's training data so it learns incorrect or malicious behavior.
Data provenance
Records of where data came from and how it has been changed, used to trust training data.
Prompt injection
Crafted input that manipulates a language model into ignoring its instructions or revealing data.
Explainability
The ability to describe in understandable terms how an AI system reached a particular output.
Algorithmic bias
Systematic unfairness in a model's outputs toward certain groups, often inherited from training data.

Domain 2: Security governance (17%)

Exam tips

Key terms

Governance
The structures and processes by which leadership directs and controls the organization, including its security program.
Compliance
Meeting and being able to prove adherence to laws, regulations, contracts, standards and policies.
Chief information security officer (CISO)
The senior leader responsible for an organization's information security program.
Due care
Taking the reasonable protective actions a prudent person would take.
Due diligence
The ongoing investigation and verification that protections are appropriate and working.
Data owner
A business leader accountable for a set of data, including its classification and who may access it.
Policy
A high-level, mandatory statement of management intent approved by senior leadership.
Standard
A mandatory, specific requirement that supports a policy, often naming technologies or values.
Procedure
Detailed, step-by-step instructions for performing a task consistently.
Baseline
A mandatory minimum security configuration for a type of system.
Guideline
A non-mandatory recommendation or best-practice suggestion.
Regulation
A detailed rule issued by a government agency that has the force of law.
GDPR
The EU General Data Protection Regulation, protecting the personal data of people in the EU.
HIPAA
A US law that protects health information held by healthcare organizations and their business associates.
PCI DSS
The Payment Card Industry Data Security Standard, a contractual standard for protecting payment card data.
Jurisdiction
The legal authority that applies based on location of the organization, data or people involved.
Risk appetite
The overall amount and type of risk an organization is willing to pursue or retain to meet its objectives.
Risk tolerance
The acceptable, usually measurable, variation around risk appetite for a specific objective.
Risk owner
The person accountable for managing a particular risk, including accepting residual risk.
Risk capacity
The maximum amount of risk an organization can absorb before it can no longer meet its obligations.
Risk exception
A formally approved and documented deviation from a policy or control, with the risk accepted by its owner.
Third-party risk
Risk arising from vendors, suppliers, contractors and other external parties an organization relies on.
Service level agreement (SLA)
A contract section defining measurable service levels, such as uptime, and remedies if they are not met.
Right to audit
A contract clause allowing the customer to review or test the vendor's security controls.
Supply chain attack
An attack that compromises a trusted supplier's product or service to reach its customers.
Non-disclosure agreement (NDA)
A contract in which parties agree to protect each other's confidential information.
Social engineering
Manipulating people into revealing information or taking actions that weaken security.
Spear phishing
A phishing attack tailored to a specific individual or small group.
Business email compromise
Fraud in which attackers impersonate a trusted party by email to trick staff into sending money or data.
Pretexting
Creating a false scenario or identity to persuade a victim to share information or grant access.
Security culture
The shared values and behaviors that make secure practices normal throughout an organization.
Metric
A quantifiable measurement tracked over time to evaluate some aspect of security.
Key performance indicator (KPI)
A measure of how well a process or control is performing against a target.
Key risk indicator (KRI)
A forward-looking measure that warns when risk is rising toward or beyond tolerance.
Dashboard
A visual display summarizing key metrics and their status for quick review.
Mean time to detect (MTTD)
The average time between an incident starting and the organization detecting it.

Domain 3: Identity & access management concepts (20%)

Exam tips

Key terms

Identification
Claiming an identity, for example by entering a username.
Subject
An active entity, such as a user or process, that requests access to a resource.
Object
A passive resource, such as a file or database, that a subject wants to access.
Accountability
The ability to trace actions to a specific individual, supported by unique IDs and logging.
Account lockout
Temporarily disabling an account after repeated failed authentication attempts.
Least privilege
Granting only the minimum access needed to perform a job, for only as long as it is needed.
Need to know
Restricting access to specific information to people whose current task requires it.
Separation of duties
Dividing a sensitive task among multiple people so no one person can complete it alone.
Collusion
Two or more people cooperating to bypass controls such as separation of duties.
Job rotation
Periodically moving staff between roles to reduce fraud risk and spread knowledge.
Provisioning
Creating an identity and granting approved initial access.
Deprovisioning
Disabling or removing an identity's access when it is no longer needed.
Privilege creep
The gradual accumulation of unnecessary access rights as a person changes roles.
Orphaned account
An active account with no current owner, such as one left behind by a former employee.
Joiner, mover, leaver
A common name for the lifecycle process covering new hires, role changes and departures.
Discretionary access control (DAC)
A model in which the resource owner decides who may access it.
Mandatory access control (MAC)
A model in which the system enforces access by comparing subject clearances with object labels; owners cannot override it.
Role-based access control (RBAC)
A model that grants permissions to job roles and assigns users to those roles.
Rule-based access control
A model that applies administrator-defined rules to all subjects, such as firewall rules or time-of-day limits.
Access control list (ACL)
A list attached to an object that specifies which subjects have which permissions.
Privileged account
An account with elevated rights, such as administrator, root or a powerful service account.
Privileged access management (PAM)
Practices and tools for controlling, limiting and monitoring privileged accounts.
Just-in-time access
Granting elevated privileges only when needed for a specific task and removing them afterward.
Password vault
A secure system that stores, rotates and controls check-out of privileged credentials.
Break-glass account
A tightly controlled emergency account used only when normal access methods fail.
Single sign-on (SSO)
Authenticating once to gain access to multiple applications without logging in again.
Identity provider (IdP)
The trusted service that authenticates users and issues assertions or tokens about them.
Federation
A trust relationship that lets identities from one organization be used to access another's resources.
SAML
Security Assertion Markup Language, an XML-based standard for exchanging signed authentication assertions.
OAuth
An authorization framework that lets users grant applications limited access to their resources without sharing passwords.
Tailgating
An unauthorized person following an authorized person through a secured entrance without their knowledge.
Piggybacking
An unauthorized person entering with the knowledge or consent of an authorized person.
Access control vestibule
A two-door entry space that admits one authenticated person at a time; formerly called a mantrap.
CCTV
Closed-circuit television cameras used to deter, monitor and record activity.
Fail-safe
A design that defaults to an open or safe state for people when a failure occurs, such as exit doors unlocking during a fire.
Access review
A periodic check by owners or managers to confirm that users' access is still appropriate.
Recertification
Formally re-approving a user's existing access as part of a review.
Dormant account
An account that has not been used for an extended period.
Rubber-stamping
Approving access in a review without genuinely evaluating it.
Entitlement
A specific permission or access right granted to an identity.

Domain 4: Networking & cloud security concepts (22%)

Exam tips

Key terms

OSI model
A seven-layer reference model describing network communication from physical signals to applications.
TCP
Transmission Control Protocol, a connection-oriented, reliable transport protocol that uses a three-way handshake.
UDP
User Datagram Protocol, a connectionless transport protocol that is fast but does not guarantee delivery.
Port
A number that identifies a specific service or application on a host.
Private IP address
An address from reserved ranges used inside networks and not routed on the public internet.
NAT
Network address translation, which maps private internal addresses to public addresses.
DDoS
Distributed denial of service: an attack from many sources that overwhelms a target to make it unavailable.
Botnet
A network of compromised devices controlled by an attacker, often used for DDoS or spam.
On-path (man-in-the-middle) attack
An attack in which the attacker secretly intercepts and possibly alters communication between two parties.
Worm
Malware that replicates and spreads across networks without user action.
Spoofing
Falsifying an identity such as an IP address, email sender or MAC address to gain trust.
Side-channel attack
An attack that infers secrets from physical characteristics like timing, power use or emissions.
Stateful firewall
A firewall that tracks connections and allows return traffic for established sessions.
Implicit deny
A default rule that blocks any traffic not explicitly allowed.
IDS
Intrusion detection system: monitors for suspicious activity and generates alerts.
IPS
Intrusion prevention system: sits inline and can automatically block malicious traffic.
False negative
A failure to detect actual malicious activity.
VPN
Virtual private network: an encrypted tunnel that protects data crossing an untrusted network.
Segmentation
Dividing a network into zones with controlled traffic between them to limit the spread of attacks.
VLAN
Virtual local area network: a logical network created on switches to separate traffic at layer 2.
DMZ (screened subnet)
A network zone between the internet and the internal network that hosts public-facing services.
Micro-segmentation
Fine-grained, often software-defined, isolation of individual workloads with their own access policies.
Lateral movement
An attacker moving from one compromised system to others within a network.
Defense in depth
Using multiple overlapping layers of security controls so one failure does not cause a breach.
Zero trust
A security model that grants no implicit trust based on network location and verifies every access request.
Assume breach
A zero trust principle of designing defenses as if attackers are already inside the environment.
Device posture
The security state of a device, such as patch level and endpoint protection, used in access decisions.
Policy enforcement point
The component that allows or blocks a connection based on a policy decision.
ZTNA
Zero trust network access: granting verified users on verified devices access to specific applications rather than the whole network.
Rapid elasticity
The ability to scale cloud resources out or in quickly, often automatically, to match demand.
Measured service
Metering of cloud resource usage so customers pay for what they consume.
Multi-tenancy
Serving multiple customers from shared infrastructure while keeping them logically isolated.
IaaS
Infrastructure as a Service: virtual servers, storage and networks where the customer manages the OS and above.
PaaS
Platform as a Service: a managed runtime or platform where the customer manages applications and data.
SaaS
Software as a Service: a complete application managed by the provider; the customer manages data and access.
Public cloud
Cloud infrastructure owned by a provider and shared by many customers over the internet.
Private cloud
Cloud infrastructure dedicated to a single organization, hosted on-premises or by a third party.
Community cloud
Cloud infrastructure shared by several organizations with common requirements or missions.
Hybrid cloud
A combination of two or more deployment models connected so data and applications can move between them.
Multi-cloud
Using services from more than one public cloud provider.
Shared responsibility model
The division of security duties between a cloud provider and its customer, which varies by service model.
Security of the cloud
The provider's responsibility for physical facilities, hardware and the virtualization layer.
Security in the cloud
The customer's responsibility for its data, identities, access and configurations.
UPS
Uninterruptible power supply: a battery-based device that keeps equipment running during short power interruptions.
HVAC
Heating, ventilation and air conditioning, which keeps data center temperature and humidity within safe ranges.

Domain 5: Security operations & incident response (17%)

Exam tips

Key terms

Data classification
Assigning data to sensitivity levels that determine how it must be protected.
Labeling
Marking data or media with its classification so it is handled correctly.
Retention policy
Rules stating how long each type of data must be kept and how it is disposed of.
Data remanence
Residual data that remains on media after deletion or formatting.
Degaussing
Erasing magnetic media with a strong magnetic field; ineffective on solid-state drives.
Cryptographic erase
Sanitizing encrypted media by securely destroying its encryption keys.
Symmetric encryption
Encryption that uses the same secret key to encrypt and decrypt; fast and used for bulk data.
Asymmetric encryption
Encryption using a public and private key pair; slower, used for key exchange and digital signatures.
Hashing
A one-way function producing a fixed-size digest used to verify integrity.
Digital signature
A hash of data encrypted with the signer's private key, proving origin and integrity.
Salt
A random value added to a password before hashing so identical passwords yield different hashes.
PKI
Public key infrastructure: the certificate authorities, certificates and processes that bind public keys to identities.
Log
A record of events generated by a system, application or device.
SIEM
Security information and event management: a system that collects, normalizes, correlates and alerts on log data.
Correlation
Linking related events from different sources to identify patterns that suggest an attack.
Event triage
Rapidly assessing alerts to determine their validity, severity and priority for response.
Alert fatigue
Desensitization caused by excessive alerts, leading analysts to miss real threats.
NTP
Network Time Protocol, used to synchronize clocks so logs from different systems line up.
Hardening
Reducing a system's attack surface by removing unneeded components and applying secure settings.
Attack surface
All the points where an attacker could attempt to enter or extract data from a system.
Configuration drift
Gradual, unapproved divergence of a system's settings from its approved baseline.
Patch management
The process of identifying, testing, deploying and verifying software updates.
Change advisory board (CAB)
A group that reviews and approves significant changes to IT systems.
Rollback plan
Steps to restore the previous state if a change fails.
Vulnerability scan
An automated check that identifies known weaknesses without exploiting them.
Penetration test
An authorized, scoped attempt to exploit vulnerabilities to demonstrate real risk.
CVE
Common Vulnerabilities and Exposures: unique public identifiers for known vulnerabilities.
CVSS
Common Vulnerability Scoring System: a 0 to 10 scale describing a vulnerability's severity.
Credentialed scan
A scan that logs in to systems to inspect them in detail, producing more accurate results.
Rules of engagement
The written scope, timing and limits that authorize and govern a security test.
Incident response plan
A documented approach defining roles, procedures and communication for handling security incidents.
CSIRT
Computer security incident response team: the group responsible for responding to incidents.
Containment
Actions that limit the spread and impact of an incident.
Eradication
Removing the root cause of an incident, such as malware or an exploited vulnerability.
Chain of custody
Documentation of who collected, handled and stored evidence, and when, to preserve its integrity.
Tabletop exercise
A discussion-based walkthrough of a simulated incident used to test plans and roles.
Business impact analysis (BIA)
An analysis identifying critical functions and the impact of their disruption over time.
Recovery time objective (RTO)
The target time within which a system must be restored after a disruption.
Recovery point objective (RPO)
The maximum acceptable data loss, measured as time since the last good copy.
Incremental backup
A backup of data changed since the last backup of any type.
Differential backup
A backup of all data changed since the last full backup.
Hot site
A fully equipped alternate site with current data that can take over almost immediately.
Acceptable use policy (AUP)
A policy defining permitted and prohibited uses of organizational systems and data.
BYOD
Bring your own device: allowing personally owned devices to access organizational resources under set rules.
Mobile device management (MDM)
Software that enforces security settings on mobile devices and can remotely lock or wipe them.
Passphrase
A long password made of several words, easier to remember and harder to guess than a short complex password.
Privacy notice
A public statement explaining how an organization collects, uses, shares and protects personal data.
Study CC for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CC study plan