# ISC2 CC Exam Preparation Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/isc2-cc-exam-prep-course-self-paced>

## Overview

This self-paced course prepares newcomers to sit the ISC2 Certified in Cybersecurity (CC) exam. It follows the exam outline that took effect September 1, 2026, with one module for each of its five domains, and assumes no prior security or IT experience.

Learners cover security principles, security governance, identity and access management, networking and cloud security, and security operations and incident response. Every module ends with practice questions drawn from its domain.

## What you'll learn

- Explain how confidentiality, integrity, and availability apply to a described situation.
- Distinguish authentication, authorization, and accounting, and explain what non-repudiation provides.
- Describe the stages of the risk management lifecycle and match a described decision to a risk treatment option.
- Classify a described safeguard as a technical, administrative, or physical control.
- Apply the ISC2 Code of Ethics to a described professional situation.
- Explain the purpose of a governance, risk, and compliance program.
- Distinguish business continuity from disaster recovery and identify what each preserves.
- Recognize social engineering and phishing attempts, and identify the awareness practices that reduce them.
- Describe the identity life cycle from provisioning through deprovisioning.
- Apply least privilege and separation of duties to a described access request.
- Compare common access control models and select the one that fits a requirement.
- Identify the layers of the OSI and TCP/IP models and explain what firewalls, VPNs, and segmentation each protect against.
- Explain defense in depth and the core principle of zero trust.
- Identify the five characteristics of cloud computing and apply the shared responsibility model.
- Describe the incident response process and what a tabletop exercise is meant to reveal.

## Curriculum

#### Module 1: Security Principles

- Lessons: 
  - Confidentiality, Integrity, and Availability
  - Authentication, Authorization, Accounting, Non-repudiation, and Privacy
  - The Risk Management Lifecycle
  - Governance Concepts: Laws, Frameworks, Policies, Standards, and Procedures
  - Control Types and Professional Ethics

- Applied activity: Learners review a short description of a small company that has just discovered customer records were exposed, and identify which part of the CIA triad was affected, which control types were missing, and which risk treatment option the company chose after the fact.

#### Module 2: Security Governance

- Lessons: 
  - Governance, Risk, and Compliance: Purpose and Frameworks
  - Redundancy: Business Continuity and Disaster Recovery
  - Security Awareness and Organizational Culture
  - Measuring Cybersecurity Effectiveness

- Applied activity: Learners review a short scenario describing an organization whose staff reuse passwords and click simulated phishing messages, and choose the awareness and measurement changes that would address the behavior, including which metric would show whether the change worked.

#### Module 3: Identity and Access Management (IAM) Concepts

- Lessons: 
  - The Identity Life Cycle: Roles, Provisioning, Review, and Deprovisioning
  - Least Privilege and Separation of Duties
  - Access Control Models

- Applied activity: Learners review a short scenario describing an employee who has changed jobs three times inside the same company and still holds every permission ever granted, and identify which life cycle step failed, what an access review should have caught, and which principle was violated.

#### Module 4: Networking and Cloud Security Concepts

- Lessons: 
  - Network Concepts: OSI and TCP/IP Models, IPv4, IPv6, and VPNs
  - Firewalls, Wireless, and Embedded Systems
  - Network Security Architecture: Segmentation, Defense in Depth, and Zero Trust
  - Cloud Security: Characteristics, Models, and Shared Responsibility

- Applied activity: Learners review a short description of a small office network that has moved its file storage to a cloud service, and identify which protections belong to the provider, which remain the customer's, and where segmentation would limit the damage from one compromised laptop.

#### Module 5: Security Operations and Incident Response

- Lessons: 
  - Data Security: Handling and Encryption
  - Security Operations: Logging, Monitoring, Triage, and Threat Actors
  - Incident Response Plans, Exercises, and Asset Protection
  - Security Testing: Team Colors and Application Testing

## Pricing

**Tuition:** $899
