Cybersecurity · Free

ISC2 Certified in Cybersecurity (CC) Exam Prep

Free preparation for the ISC2 Certified in Cybersecurity (CC) exam, mapped to the five domains of the outline effective 1 September 2026: security principles, security governance, identity and access management, networking and cloud security, and security operations and incident response, with original practice questions on every domain. Exam preparation only: the EDWartens certificate is not the CC, which is earned only by passing ISC2's exam.

13 modules 8h 45m of video English · self-paced

Inside the course

ISC2 Certified in Cybersecurity (CC) Exam Prep: Syllabus at a glanceISC2 Certified in Cybersecurity (CC) Exam Prep: What you will be able to doISC2 Certified in Cybersecurity (CC) Exam Prep: Tools and credits

From the lessons

  • Certified in Cybersecurity (CC) exam changes 2026 - What is changing and what is staying the same?

    How the CC exam works, and how to study for it

    ThorTeaches.com: CISSP, CC, CISM, GenAI training

  • CC | Risk Management - Part 5 | Certified in Cybersecurity (CC)

    Risk management: assets, threats, vulnerabilities and treatment

    ThorTeaches.com: CISSP, CC, CISM, GenAI training

  • ISC2 CC 2026 Complete Course | Updated Exam Outline – Domain 2

    Security governance: GRC, continuity, recovery, awareness and metrics

    Computer Networks Decoded

  • Certified in Cybersecurity | The OSI Model - Part 2

    Networking fundamentals: OSI, TCP/IP, addressing, ports and VPNs

    ThorTeaches.com: CISSP, CC, CISM, GenAI training

  • What is Zero Trust Network Access (ZTNA)? The Zero Trust Model, Framework and Technologies Explained

    Network security architecture and cloud security

    The CISO Perspective

  • Security Operations Center (SOC) Explained

    Security operations: logging, monitoring, triage and threat intelligence

    IBM Technology

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Explain the CIA triad, AAA, non-repudiation and privacy; work through a risk assessment and choose a treatment; tell technical, administrative and physical controls apart; apply the ISC2 Code of Ethics, due care and due diligence; describe GRC, business continuity, disaster recovery, awareness and security metrics; run an identity life cycle with least privilege and separation of duties; explain the OSI and TCP/IP models, common ports, segmentation, zero trust and the cloud shared responsibility model; classify and protect data with the right encryption; triage security events and follow an incident response plan; and answer CC-style scenario questions with a clear method.

  • Know the 2026 CC exam format, the five domains and their weights, and how to break down a scenario question
  • Apply the CIA triad, AAA, MFA, non-repudiation and privacy to real incidents
  • Score and calculate risk with SLE and ALE, and choose avoid, reduce, transfer or accept
  • Classify controls, apply due care and due diligence, and order the ISC2 Code of Ethics canons
  • Set MTD, RTO and RPO, choose backups and sites, and measure security with KRIs
  • Run an identity life cycle with least privilege, separation of duties and the right access model
  • Explain OSI and TCP/IP, ports, firewalls, segmentation, zero trust and cloud shared responsibility
  • Handle and encrypt data correctly, triage alerts, follow the IR life cycle and plan security testing

For you

Taking ISC2 Certified in Cybersecurity (CC) Exam Prep from the United States

The course project · about 8 hours

First security analyst at a 60-person logistics firm: risk register, access review, ransomware playbook and monthly security report

Act as the newly hired junior security analyst at a small freight forwarding company. Build its first risk register with ALE for the top risks, run an access review of the finance system, write the ransomware incident playbook and run it as a tabletop, and report the month's security metrics and key risk indicators to the managing director. The sample pack shows each document for a fictional firm.

Sample document pack, 5 documents, filled in for the scenario

  • Risk registerInformation security risk register
  • RegisterAccess review: finance system, October
  • ProcedureRansomware incident playbook
  • ReportTabletop exercise record: ransomware on a finance laptop
  • ReportMonthly security report: October

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

13 modules · 37 lessons · 8h 45m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01How the CC exam works, and how to study for it39m
  2. 02Security concepts: CIA, AAA, non-repudiation and privacy32m
  3. 03Risk management: assets, threats, vulnerabilities and treatment1h 18m
  4. 04Governance, controls and the ISC2 Code of Ethics41m
  5. 05Security governance: GRC, continuity, recovery, awareness and metrics47m
  6. 06Identity and access management: the identity life cycle and access models42m
  7. 07Networking fundamentals: OSI, TCP/IP, addressing, ports and VPNs1h 29m
  8. 08Network threats, firewalls, wireless and embedded systems49m

Requirements

Who it is for
Beginner. For students, career changers and IT staff preparing for the ISC2 CC exam. No security experience is needed; basic computer use and curiosity are enough.
Software
A web browser. Wireshark (free) and a free virtual machine tool such as VirtualBox are useful for the optional network exercises, which run only on your own computer. What to download, and how
Hardware
None. A laptop that can run one small virtual machine helps with the optional lab tasks.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

Nothing to install

A web browser is enough; Wireshark and VirtualBox are optional for the network exercises, run only on your own computer.

Optional

Useful, not needed to finish the course.

  1. 01

    Wireshark

    Wireshark Foundation

    Free
    Runs on
    Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
    Account
    None needed

    Free, open source software. No licence fee for any use.

  2. 02

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

ISC2 Certified in Cybersecurity (CC) Exam Prep at a glance

ISC2 Certified in Cybersecurity (CC) Exam Prep is a free, self-paced online course from EDWartens for students, career changers and IT staff preparing for the ISC2 Certified in Cybersecurity (CC) exam. It has 13 modules and 8h 45m of video lessons by ThorTeaches.com, IBM Technology, Computer Networks Decoded and others, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Students, career changers and IT staff preparing for the ISC2 Certified in Cybersecurity (CC) exam
Format
13 self-paced modules, 8h 45m of video, written notes, a practice task per module and one final assessment.
Level
Beginner. Beginner. For students, career changers and IT staff preparing for the ISC2 CC exam. No security experience is needed; basic computer use and curiosity are enough.
Brand
Vendor-neutral
Software
A web browser. Wireshark (free) and a free virtual machine tool such as VirtualBox are useful for the optional network exercises, which run only on your own computer.
Hardware
None. A laptop that can run one small virtual machine helps with the optional lab tasks.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
ThorTeaches.com, IBM Technology, Computer Networks Decoded, The CISO Perspective (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of ISC2 Certified in Cybersecurity (CC) Exam Prep, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

What is the ISC2 Certified in Cybersecurity (CC) exam?

The CC is ISC2's entry-level cybersecurity certification exam, for people with no work experience in security. Under the outline effective 1 September 2026 it uses computerized adaptive testing with 100 to 125 items in two hours across five domains, and the passing grade is 700 out of 1000; check the current details on ISC2's official CC exam outline page at isc2.org/certifications/cc/cc-certification-exam-outline.

Is the ISC2 CC exam still free?

No longer for new candidates. ISC2's One Million Certified in Cybersecurity programme closed to new enrolments on 20 May 2026; people who already hold an unexpired exam code from it must schedule and sit the exam by 31 December 2026, and everyone else buys the exam from ISC2, with the fee paid to ISC2. This EDWartens course is free to learn either way.

Is this the official ISC2 CC course, and does passing it give me the CC?

No. It is an independent preparation course built on free lessons by ThorTeaches.com, IBM Technology and other educators, with original EDWartens notes and practice questions. ISC2, CC and Certified in Cybersecurity are registered marks of ISC2, Inc.; EDWartens is not affiliated with or endorsed by ISC2, and the CC is earned only by passing ISC2's own exam.

Who is this ISC2 CC exam prep course for, and what do I need to start?

It is for students, career changers, IT support staff and anyone aiming at a first job such as junior security analyst or SOC analyst. No security experience is needed, and the only software is a web browser; Wireshark and VirtualBox are optional for the network exercises on your own computer.

Does the course follow the new 2026 CC exam outline?

Yes. The twelve teaching modules map to the five domains effective 1 September 2026: Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response, including the AI content ISC2 added across the domains. Some videos were recorded for the 2022 outline, and the notes say where the 2026 outline differs.

How long does the course take, and is it free to learn?

It takes about 13 hours at your own pace, of which about 8.8 hours is video, plus about 8 hours for the optional project. Every module, the notes, the 148 original practice questions, the project and the final assessment are free to learn.

What certificate do I get, and how is it verified?

You get an EDWartens verifiable certificate of completion when you finish the modules and pass the 15-question final at 60 percent. It carries a unique certificate number and a QR code that open a public verification page showing the course, the modules covered and your final score. It is not the ISC2 CC certification.

What jobs can the ISC2 CC lead to?

The CC is a common first step towards roles such as SOC analyst, junior security analyst, IT support with security duties and GRC assistant, and towards ISC2's SSCP and CISSP later. IT services firms, SOC providers, banks and telecoms hire entry-level security staff, and a foundation certification such as the CC or CompTIA Security+ helps a candidate without experience show the basics.

What you walk away with

Your certificate for ISC2 Certified in Cybersecurity (CC) Exam Prep

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for ISC2 Certified in Cybersecurity (CC) Exam Prep
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$23.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • ThorTeaches.comThor Pedersen's CC lessons: the 2026 exam changes, deconstructing CC questions, the IAAA model, risk management, laws and regulations, physical security, disaster recovery, identity and logical access, the OSI model, attackers and attacks, zero-day exploits, wireless networks, cloud and virtualization, data handling, cryptography, incident management, scheduling the exam and the adaptive (CAT) format
  • IBM Technologythe explainers on the CIA triad, the five principles of security architecture, building a cybersecurity framework, IAM, network security architecture, quantum-safe cryptography, SIEM, the SOC, threat hunting, the 2026 Threat Intelligence Index, red and blue teams and application security
  • Computer Networks Decodedthe ISC2 CC 2026 complete course lessons for Domains 1 to 4 of the outline effective 1 September 2026
  • The CISO Perspectivethe lesson on zero trust network access and the zero trust model

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.