Skip to content
CBT Nuggets
DemoBook a Demo

(ISC)² CC – Certified in Cybersecurity

This ISC2 CC - Certified in Cybersecurity course is designed to lay the foundation for a professional cybersecurity career, and help you study for your ISC2 CC certification. You'll learn to understand the ethical and risk-based frameworks that define the industry, then dive into business continuity and incident response to learn how organizations survive and recover from disruption. From there, you'll explore cybersecurity topics such as access control and network security, and understand the mechanics of protecting digital borders and managing identities. Finally, you'll explore security operations for real-world system defense. To make sure you're ready for exam day, the course includes unlimited ISC2 Certified in Cybersecurity practice exams to build your confidence and reinforce skills.

Updated May 2023

10Skills
66Videos
9hTotal

Who This Course Is For

This ISC2 CC training is considered foundational-level ISC2 training that's designed for cybersecurity specialists. This cybersecurity skills course is valuable for new IT professionals with at least a year of experience with security, and experienced cybersecurity specialists looking to validate their ISC2 skills.

Skills Your Team Will Gain

  • Foundational cybersecurity principles
  • Basics of cybersecurity technologies and devices
  • Steps of incident response and disaster recovery
  • The role cybersecurity plays in business continuity

Course Curriculum

One skill is free to watch — no signup needed. The other 9 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Understanding Information Assurance

Bob SalmansDuration: 48m12 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Understanding Information AssuranceFree48m · 12 videos
  • Premium skill.Discussing Risk Management, Controls, Ethics and Governance51m · 16 videos
  • Premium skill.Exploring BC, DR & IR Concepts49m · 16 videos
  • Premium skill.Reviewing Access Control Concepts53m · 16 videos
  • Premium skill.Exploring Security Policies and Training54m · 16 videos
  • Premium skill.Understanding Data Security and System Hardening55m · 16 videos
  • Premium skill.Discussing Network Security Infrastructure55m · 16 videos
  • Premium skill.Exploring Network Threats and Attacks58m · 14 videos
  • Premium skill.Understanding Computer Networking56m · 16 videos
  • Premium skill.Exploring On-Premise Network Infrastructure52m · 14 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

CC – Certified in Cybersecurity

ISC2 Certified in Cybersecurity (CC) is an entry-level cybersecurity certification for newcomers, IT professionals, career changers, students and recent graduates. It validates foundational cybersecurity knowledge for entry- or junior-level roles, in...

Exam CCLevel Entry-levelDifficulty BeginnerCost $200
Security PrinciplesSecurity GovernanceIdentity and Access Management (IAM) ConceptsNetworking and Cloud Security ConceptsSecurity Operations and Incident ResponseRisk management concepts
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security teams need a common baseline before they can consistently handle access control, policy enforcement, incident response, and day-to-day security operations without creating avoidable risk. For organizations pursuing SOC 2, CMMC, or internal audit readiness, an uneven security baseline is an exposure — this training closes that gap before it becomes a finding. This foundational ISC2 CC training is suited to IT Directors at mid-market firms onboarding junior security staff, cross-training help desk or systems personnel into security responsibilities, or standardizing knowledge across newer cybersecurity practitioners. At 8–9 hours total, this course fits comfortably into a structured onboarding sprint or can be distributed across two weeks without disrupting day-to-day operations. It also prepares learners for the ISC2 CC exam, giving technology leaders managing hybrid teams a clear workforce-readiness outcome alongside certification alignment.

Teams complete this course ready to apply foundational security concepts across core ISC2 CC domains — reducing the ramp time for new hires and ensuring consistent coverage across mixed-experience cohorts.

  • Security principles, governance, and risk
  • Business continuity, disaster recovery, and incident response
  • Access controls and foundational network security
  • Security operations concepts, including logical and physical controls

This course is the right fit for entry-level hires and practitioners closing foundational gaps — not for advanced specialists already operating at a senior technical level. For change management, assign it alongside your internal policies and operational procedures so teams can connect foundational security concepts to your environment. Whether you're onboarding a cohort of five or rolling this out across a distributed team, CBT Nuggets Playlists and Team Reporting let you assign, sequence, and track completion at scale.

Team Impact

How this training helps your team succeed

IT teams rely on foundational security judgment to reduce preventable mistakes, especially when newer staff begin taking on operational security work. This training maps to practical areas teams encounter every day, including policy awareness, access control decisions, system hardening, and network threat recognition.

In real-world environments, this helps teams:

  • Support safer onboarding of junior cybersecurity staff — so new hires arrive with a consistent baseline on access control, acceptable use, and security ethics before they touch production systems.
  • Reduce friction during incident response and continuity planning sessions by ensuring junior team members can discuss recovery objectives, escalation paths, and continuity priorities — not just the senior staff in the room.
  • Reduce the risk of misconfigurations and policy drift that occur when team members apply access control, data protection, or hardening practices inconsistently — a common failure mode when staff come from varied backgrounds or self-taught paths.
  • Strengthen day-to-day network security awareness so team members can recognize common threat patterns and make faster, better-informed escalation decisions without relying on a senior analyst for every call.

For IT Directors at mid-market firms and technology leaders managing hybrid teams, the value is workforce readiness and risk reduction: teams complete this training to establish a common security language before moving into tool-specific administration, advanced defense work, or higher-stakes compliance responsibilities.

After completion

Capabilities your team walks away with

Knowledge

  • Security principles, including the CIA triad, authentication, non-repudiation, and privacy, and how they support foundational cybersecurity work.
  • Risk management basics, including controls, ethics, and governance concepts used in security decision-making.
  • Business continuity, disaster recovery, and incident response concepts at a foundational level.
  • Access control principles relevant to protecting systems, data, and physical security.
  • Security policy, security awareness, training, and code of ethics concepts that support organizational security practices.
  • Core network security concepts, including infrastructure components, common threats, and attack vectors.
  • Foundational data security and system hardening principles for on-premises and cloud environments.
  • Computer networking and infrastructure basics relevant to foundational cybersecurity work.
  • Foundational security operations concepts, including data handling, logging, and configuration management.

Ability

  • Apply a shared vocabulary of foundational security concepts to entry-level cybersecurity operations, reducing onboarding friction for new team members.
  • Recognize and discuss common security requirements related to access control, physical security, data protection, and hardening efforts.
  • Contribute to team conversations about risk, governance, resilience planning, and incident response preparation.
  • Identify foundational network security considerations, including infrastructure components and common threat areas.
  • Use foundational security principles as a baseline for supervised security responsibilities.
  • Demonstrate readiness for the (ISC)² CC certification exam, including for career changers, non-security IT staff, and practicing security professionals seeking a formal credential.
  • Establish a shared knowledge baseline across new and developing team members to support more consistent security task execution.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

(ISC)² SSCP – Systems Security Certified Practitioner

This (ISC)² Systems Security Certified Practitioner (SSCP) training is designed for cybersecurity professionals seeking hands-on expertise in securing IT systems. This course covers application security, network defense, access control mechanisms, cr...

~17h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$169one time

No subscription

One year of access to ISC2 Certified in Cybersecurity​

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Is the ISC2 Certified in Cybersecurity worth it?

Whether or not the Certified in Cybersecurity credential from ISC2 is worth it depends on your previous work experience and the positions you want to be competitive for. The ISC2 CC is an entry-level certification that is almost entirely knowledge-based. That means it's an excellent choice for brand-new IT professionals or students who just need to get their foot in the door, but may be too simplistic for working professionals.

What does ISC and (ISC)² mean in cybersecurity?

The International Information System Security Certification Consortium is a non-profit professional organization of cybersecurity professionals. While that is its official legal name, the organization is primarily known by the brand name ISC2. Historically, it was referred to as (ISC)², which stood for ISC (Information System Security) and C (Certification Consortium) "squared." In 2023, the organization transitioned to the simplified ISC2 to improve digital accessibility and global recognition. As an organization, ISC2's goal is a safe and secure cyber world, which they believe is attainable through providing training, education, and certification to cybersecurity professionals. ISC2 creates and maintains certifications to benchmark competence, technical skill, and knowledge in the career field.

Is the ISC2 CC - Certified in Cybersecurity exam hard?

No, the Certified in Cybersecurity exam is not especially difficult. The ISC2 CC exam is designed to cover the basics without posing too steep of a challenge. But with no preparation and no experience at all, the CC exam can be difficult, as it covers every foundational concept of the cybersecurity career field. The exam topics include fundamental principles of security, how incident response works, how network access gets given and restricted, and how a cybersecurity team operates.

How much does the ISC2 CC - Certified in Cybersecurity cost?

Depending on when you read this, the Certified in Cybersecurity credential from ISC2 is free. According to ISC2's website, as a part of their One Million Certified in Cybersecurity program, taking the CC certification exam is free. By registering for a free account with ISC2 and applying for the ISC2 Candidate program, you can take the Certified in Cybersecurity exam for free. A $50 annual membership fee is necessary to maintain the certification.

What's the best way to study for the ISC2 Certified in Cybersecurity?

If you're new to IT or cybersecurity, the best way to prepare for ISC2 CC is with a course like this one – one that covers all the topics of the exam with short, to the point videos from experts. Have the fundamentals of security, incident response, access control and security operations explained to you by an expert in the field, at your own pace, with clear video explanations of each topic.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.