ISC2 Certified in Cybersecurity (CC) Exam Preparation

A one-day programme covering the full ISC2 Certified in Cybersecurity exam outline. CC is the entry-level credential from the body behind the CISSP, and it is deliberately built for people with no security experience: career changers, IT support staff moving toward security, graduates, and non-technical staff in compliance or audit roles who need to hold a security conversation credibly.

The five domains are covered in a single day because CC tests recognition and understanding rather than hands-on skill. The session works through each domain with checkpoint questions, then closes with a timed practice assessment and a study plan. This is exam preparation rather than accredited delivery. ISC2 has run a free exam and training initiative for this certification, and where that is available participants are pointed to it. Anyone wanting the certification alongside a Malaysian regulatory grounding will find this pairs naturally with the PDPA and Cyber Security Act 2024 courses in the catalogue.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Exam Orientation

Exam format, domain weighting, scoring, the endorsement step after passing, and what CC does and does not qualify you for.

02

9:15 AM - 10:30 AM

Domain 1: Security Principles

The largest domain. Confidentiality, integrity, availability, authentication, non-repudiation and privacy. Risk management: identification, assessment, treatment, tolerance and the risk register. Security controls by category, technical, administrative and physical. Professional ethics and the ISC2 code. Governance elements: policies, standards, procedures and regulations, with the Malaysian PDPA and the Cyber Security Act 2024 used as the worked examples rather than the usual American ones.

03

10:30 AM - 10:45 AM

Break

04

10:45 AM - 11:30 AM

Domain 2: Business Continuity, Disaster Recovery and Incident Response

The purpose of each of the three and how they differ, which is the distinction the exam tests most often. Business continuity planning and the components of a plan. Disaster recovery, recovery sites and the recovery objectives. Incident terminology, the incident response process, and the composition of a response team.

05

11:30 AM - 12:30 PM

Domain 3: Access Control Concepts

Physical access controls: badges, guards, barriers, cameras, and the difference between a deterrent and a preventive control. Logical access controls. The principle of least privilege, segregation of duties and authorised versus unauthorised personnel. Access control models: discretionary, mandatory, role-based and rule-based, and how to recognise each from a scenario description.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:45 PM

Domain 4: Network Security

Networking concepts to the depth CC requires: the OSI and TCP/IP models, IP addressing, ports and protocols, and common network devices. Threats and attacks including denial of service, virus, worm, trojan, on-path and side-channel. Threat identification tools: IDS, IPS, antivirus, firewalls, SIEM. Network design: defence in depth, segmentation, zero trust, VLANs, VPNs, network access control and the security implications of cloud, on-premises and hybrid, plus service models and the shared responsibility line.

08

2:45 PM - 3:00 PM

Break

09

3:00 PM - 4:00 PM

Domain 5: Security Operations

Data handling: classification, labelling, retention, destruction and the data lifecycle. Encryption at rest, in transit and in use, plus hashing. System hardening, configuration management, baselines, patching and inventory. Security policies including acceptable use, bring your own device, change management, privacy and password policy. Security awareness training, and why social engineering countermeasures sit in operations rather than in technology.

10

4:00 PM - 4:45 PM

Timed Practice Assessment and Review

A timed practice set under exam conditions, scored by domain and reviewed together so each participant leaves knowing their remaining gaps.

11

4:45 PM - 5:00 PM

Exam Strategy, Study Plan and Close

Booking the exam, the endorsement process, maintaining the credential, and a personalised study plan for the weeks before the attempt.

Key Outcomes

  • Explain core security principles, risk management and control categories using Malaysian regulatory examples
  • Distinguish business continuity, disaster recovery and incident response, and describe what each contains
  • Describe physical and logical access controls and recognise the four access control models
  • Cover networking, common attacks, defensive tooling and secure network design to CC depth
  • Apply data handling, encryption, hardening and security policy concepts
  • Sit the ISC2 CC exam with a scored diagnostic and a personalised study plan behind you

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Entry level. No security experience or prerequisites required. Suitable for career changers, IT support staff, graduates, and compliance, audit or risk staff who need working security literacy.

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A timed practice assessment scored by domain plus checkpoint questions after each domain. The ISC2 exam itself is booked separately with Pearson VUE.

Certificate   Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the ISC2 credential. Certified in Cybersecurity is awarded by ISC2 only on passing its exam and completing endorsement, which are arranged separately.

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. ISC2 Certified in Cybersecurity (CC) Exam Preparation is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

ISC2 Certified in Cybersecurity (CC) Exam Preparation runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the ISC2 credential. Certified in Cybersecurity is awarded by ISC2 only on passing its exam and completing endorsement, which are arranged separately. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Entry level. No security experience or prerequisites required. Suitable for career changers, IT support staff, graduates, and compliance, audit or risk staff who need working security literacy. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.