ISC2 Certified Cloud Security Operations (CC) Practice Test

148 questions available

Build your confidence for ISC2 Certified Cloud Security Operations (CC). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
148 Practice questions
2 hours 28 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bank 148 Practice questions checked against the official objectives.
148 practice questions

Exam overview and details

ISC2 entry-level cloud security certification covering security concepts, cloud security, network security, access controls, and security operations fundamentals. Administered by ISC2. Key domains include Compliance, Cryptography, Incident Response and Network Security.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Incident Response

To capture volatile memory from a running cloud Linux instance for forensics, the responder should:

Identity and Access Management

When is sts:GetSessionToken typically appropriate compared to sts:AssumeRole?

Incident Response

Microsoft Defender for Cloud raises an incident "Possible credential dumping detected on Azure VM." First responder steps include:

Vulnerability and Configuration Management

A Lambda function still runs on Node.js 14, which AWS has marked end-of-life. What is the security concern?

Logging and Monitoring

An incident responder needs to know if a specific S3 object was downloaded. CloudTrail by default does NOT capture this. Why?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In the real world, cloud breaches are often the result of operational misconfigurations, inadequate monitoring, or slow incident response-not a lack of high-level strategy. This certification matters because it focuses on the actionable skills needed to prevent and mitigate these everyday threats. It provides a standardized framework for the critical, hands-on work of securing cloud workloads, enabling professionals to directly reduce risk, maintain business continuity, and protect sensitive data in dynamic cloud environments. The practical value lies in applying its principles to harden configurations, automate security responses, and effectively manage cloud security tools.

What this exam covers

01Compliance

Regulatory compliance and governance

02Cryptography

Encryption, hashing, and cryptographic protocols

03Incident Response

Security incident handling and response

04Network Security

Network security fundamentals and best practices

05Risk Management

Risk assessment and mitigation strategies

Frequently Asked Questions

Do I need the CISSP before taking the CC exam?

Is this certification specific to AWS, Azure, or Google Cloud?

What kind of hands-on experience is recommended?

How does the CC differ from the CCSP?

What is the exam format and duration?