An organization documents a risk it cannot remediate within budget. The leadership team decides to formally acknowledge the risk and continue operating with no additional controls. Which risk-treatment strategy did the team apply?
Cybersecurity and Applied AI career insights
© 2023-2026 Bespoke Intermedia LLC
Founded by Julian Calvo, Ed.D., M.S.
Free · 8 practice questions · Cybersecurity
8 scenario-based questions covering every domain on the exam blueprint. Original DecipherU writing with primary-source citations, not exam-question mimicry. Free to read. Pair with the $97 cert-prep add-on for domain reviews and exam-day strategy.
Read the ISC2 Certified in Cybersecurity (CC) exam overviewSee parent course
Layered on grc and compliance fundamentals
ISC2 Certified in Cybersecurity (CC) exam-ready ramp on top of GRC and Compliance Fundamentals. Five domain reviews mapped to the official ISC2 CC outline, three full-length mock exams, and the ISC2 free-exam application walkthrough.
An organization documents a risk it cannot remediate within budget. The leadership team decides to formally acknowledge the risk and continue operating with no additional controls. Which risk-treatment strategy did the team apply?
Which of the following is NOT one of the four canonical risk-treatment options recognized by NIST SP 800-39 and tested on ISC2 CC?
A company's recovery objectives for its order-processing system are RTO 4 hours and RPO 30 minutes. Which backup strategy best meets both objectives?
A government agency classifies documents at five sensitivity levels. Users hold clearances at specific levels and can only read documents at or below their clearance. The agency wants the operating system to enforce these labels programmatically. Which access-control model best matches this requirement?
A user logs in with username + password + a one-time code from a hardware token. Which combination of factors does this authentication use?
A network admin must allow web traffic from the internet to a public application but block direct internet access to internal application servers. Which architecture best fits?
Which wireless security protocol is the current best practice for new enterprise wireless networks and is the version specifically tested on the ISC2 CC exam blueprint as the current standard?
A new analyst is configuring system hardening on a database server. Which combination of steps best matches the ISC2 CC hardening framework?
Liked these 8? Get the full prep.
Adds exam-blueprint domain reviews, exam-day strategy, the authorized study resources, and the gated practice scenarios behind purchase. $97 on top of the parent course. Verified against the official blueprint 2026-05-22.
Other cert practice sets. Sixteen more cert-prep modules ship with practice question sets:
Join cybersecurity professionals receiving weekly intelligence on threats, job market trends, salary data, and career growth strategies.
By subscribing you agree to our privacy policy. Unsubscribe anytime.