ISC2 Certified in Cybersecurity (CC) Exam Preparation
A one-day programme covering the full ISC2 Certified in Cybersecurity exam outline. CC is the entry-level credential from the body behind the CISSP, and it is deliberately built for people with no security experience: career changers, IT support staff moving toward security, graduates, and non-technical staff in compliance or audit roles who need to hold a security conversation credibly.
The five domains are covered in a single day because CC tests recognition and understanding rather than hands-on skill. The session works through each domain with checkpoint questions, then closes with a timed practice assessment and a study plan. This is exam preparation rather than accredited delivery. ISC2 has run a free exam and training initiative for this certification, and where that is available participants are pointed to it. Anyone wanting the certification alongside a Malaysian regulatory grounding will find this pairs naturally with the PDPA and Cyber Security Act 2024 courses in the catalogue.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Exam Orientation
Exam format, domain weighting, scoring, the endorsement step after passing, and what CC does and does not qualify you for.
9:15 AM - 10:30 AM
Domain 1: Security Principles
The largest domain. Confidentiality, integrity, availability, authentication, non-repudiation and privacy. Risk management: identification, assessment, treatment, tolerance and the risk register. Security controls by category, technical, administrative and physical. Professional ethics and the ISC2 code. Governance elements: policies, standards, procedures and regulations, with the Malaysian PDPA and the Cyber Security Act 2024 used as the worked examples rather than the usual American ones.
10:30 AM - 10:45 AM
Break
10:45 AM - 11:30 AM
Domain 2: Business Continuity, Disaster Recovery and Incident Response
The purpose of each of the three and how they differ, which is the distinction the exam tests most often. Business continuity planning and the components of a plan. Disaster recovery, recovery sites and the recovery objectives. Incident terminology, the incident response process, and the composition of a response team.
11:30 AM - 12:30 PM
Domain 3: Access Control Concepts
Physical access controls: badges, guards, barriers, cameras, and the difference between a deterrent and a preventive control. Logical access controls. The principle of least privilege, segregation of duties and authorised versus unauthorised personnel. Access control models: discretionary, mandatory, role-based and rule-based, and how to recognise each from a scenario description.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:45 PM
Domain 4: Network Security
Networking concepts to the depth CC requires: the OSI and TCP/IP models, IP addressing, ports and protocols, and common network devices. Threats and attacks including denial of service, virus, worm, trojan, on-path and side-channel. Threat identification tools: IDS, IPS, antivirus, firewalls, SIEM. Network design: defence in depth, segmentation, zero trust, VLANs, VPNs, network access control and the security implications of cloud, on-premises and hybrid, plus service models and the shared responsibility line.
2:45 PM - 3:00 PM
Break
3:00 PM - 4:00 PM
Domain 5: Security Operations
Data handling: classification, labelling, retention, destruction and the data lifecycle. Encryption at rest, in transit and in use, plus hashing. System hardening, configuration management, baselines, patching and inventory. Security policies including acceptable use, bring your own device, change management, privacy and password policy. Security awareness training, and why social engineering countermeasures sit in operations rather than in technology.
4:00 PM - 4:45 PM
Timed Practice Assessment and Review
A timed practice set under exam conditions, scored by domain and reviewed together so each participant leaves knowing their remaining gaps.
4:45 PM - 5:00 PM
Exam Strategy, Study Plan and Close
Booking the exam, the endorsement process, maintaining the credential, and a personalised study plan for the weeks before the attempt.
Key Outcomes
- Explain core security principles, risk management and control categories using Malaysian regulatory examples
- Distinguish business continuity, disaster recovery and incident response, and describe what each contains
- Describe physical and logical access controls and recognise the four access control models
- Cover networking, common attacks, defensive tooling and secure network design to CC depth
- Apply data handling, encryption, hardening and security policy concepts
- Sit the ISC2 CC exam with a scored diagnostic and a personalised study plan behind you
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Entry level. No security experience or prerequisites required. Suitable for career changers, IT support staff, graduates, and compliance, audit or risk staff who need working security literacy.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A timed practice assessment scored by domain plus checkpoint questions after each domain. The ISC2 exam itself is booked separately with Pearson VUE.
Certificate Orbix Certificate of Completion issued to all participants upon full attendance. This is a training certificate, not the ISC2 credential. Certified in Cybersecurity is awarded by ISC2 only on passing its exam and completing endorsement, which are arranged separately.