


Rebuilt for the ISC2 CC outline effective 1 September 2026
ISC2 renamed and restructured three of the five domains, moved content between them, changed the weights, and integrated AI security concepts across all five.
Sitting on or after 1 September 2026? This course matches your exam.
Sitting before that date? You are on the previous outline. Around 13% of these questions cover topics that are not on your exam, and the domain breakdown will not map to yours. Please book on or after 1 September, or use material built for the previous outline.
Understand why every option is right or wrong
Getting a question wrong tells you little on its own. Knowing why the option you picked looked right is what changes your answer next time.
Every one of the 600 questions gives you four things:
The correct answer, and why it is correct
A specific reason each of the other three options fails
An exam tip — a rule you can carry into a question you have not seen
The exact outline objective it tests, so you know what to study
Then know exactly which domain is holding you back
A score tells you where you stand. A breakdown tells you what to do next.
Every question is tagged to one of the 20 objectives in the ISC2 CC exam outline, and each exam mirrors the official domain weights exactly.
So you do not just see 74%. You see which domain cost you the marks, and which objective inside it.
What you get
6 full-length exams, 600 questions — all written for the September 2026 outline
Exact ISC2 domain weights — 24 Security Principles, 17 Security Governance, 20 IAM, 21 Networking and Cloud, 18 Security Operations and Incident Response
Every choice explained — four options, four explanations
An exam tip on every question — transferable rules, not restatements of the answer
Objective-level tagging — results point to a topic, not just a domain
120 minutes per exam — the same clock as the real thing
Full coverage of the new outline
All 20 objectives, including everything new in 2026:
Governance, Risk and Compliance as a planned programme
Measuring effectiveness — metrics, Key Risk Indicators, dashboards, board reporting
Identity life cycle — roles, provisioning, review, deprovisioning
Physical access controls alongside logical ones
Cloud security in full — characteristics, service and deployment models, shared responsibility
Security testing — red, blue and purple teaming, scanning, static and dynamic analysis, threat modeling, physical penetration testing
Zero Trust, defense in depth, segmentation
Asset protection — lifecycle, end-of-life software, configuration and change management
Due care, due diligence, and the ISC2 Code of Ethics
AI security across all five domains — model poisoning, bias in automated decisions, model drift, AI service accounts, impossible-travel detection, and the risks of public AI assistants at work
Who this is for
Anyone sitting the ISC2 CC on or after 1 September 2026
Career changers — the CC has no prerequisites, and neither does this course
Students and recent graduates
Junior IT staff moving into security
Business leaders who need foundational security literacy
Created by
Dr. Nasser Alaeddine — PhD, CISSP, CISM. Over ten years of university-level cybersecurity teaching and more than twenty years of practice.