GIAC Critical Controls Certification Exam Prep
Free practice questions

Free GCCC Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,052-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GCCC exam has 75 questions and runs 2 hours.

These 10 free GCCC questions are organized by exam domain, so you can see how each part of the GIAC Critical Controls Certification blueprint is tested. Reveal the answer and explanation under each question.

Domain 5: Background on CIS Controls, Standards, and Governance

Question 1

A domain administrator uses a single account with Domain Admin rights for all daily work, including reading email and browsing the web. An auditor flags this. Which CIS Safeguard is being violated, and under which Control does it fall?

Show answer & explanation

Correct answer: B - Restrict Administrator Privileges to Dedicated Administrator Accounts, under Control 5

Question 2

During an account review, an auditor finds a contractor account with no login activity for 60 days that remains enabled. Which Safeguard does this finding map to, and what is the defined threshold?

Show answer & explanation

Correct answer: A - Disable Dormant Accounts - 45 days of inactivity

Domain 6: Continuous Vulnerability Management

Question 3

An enterprise enforces MFA on its VPN and on all administrative accounts, but its internet-facing customer portal still accepts a password alone. Which Safeguard is unmet?

Show answer & explanation

Correct answer: C - Require MFA for Externally-Exposed Applications, which covers enterprise and third-party internet-facing apps

Question 4

An employee is terminated. The IT team deletes the user's account immediately to ensure no further access. The security auditor identifies a problem with this approach. What is the concern?

Show answer & explanation

Correct answer: C - Deletion may destroy audit trails; disabling is preferred to preserve them

Domain 7: Data Protection

Question 5

An internal vulnerability scan returns far fewer findings than expected and misses missing OS patches that the desktop team has independently confirmed. The scanner reaches every host and enumerates open services successfully, the plugin feed updated this morning, and the asset list is accurate. What is the MOST likely cause?

Show answer & explanation

Correct answer: B - The scans are unauthenticated and cannot inspect host-level state

Question 6

A scan produces 4,000 findings. Two stand out: a CVSS 9.8 flaw on an isolated internal lab host with no sensitive data, and a CVSS 6.4 flaw on an internet-facing production server holding customer records, with a known exploit in the wild. Consistent with Control 7, which should be remediated first, and why?

Show answer & explanation

Correct answer: B - The CVSS 6.4 finding, because remediation is risk-based, weighing exposure, exploitability, and asset sensitivity

Domain 19: Service Provider Management

Question 7

An enterprise has fully implemented every Implementation Group 1 Safeguard and is deciding what to tackle next. Its CISO claims that reaching IG2 requires implementing 130 additional Safeguards. What is the correct characterization of the remaining work?

Show answer & explanation

Correct answer: A - IG2 requires 74 additional Safeguards, bringing the cumulative total to 130

Question 8

A systems administrator must harden 300 Windows Server hosts and needs authoritative, platform-specific settings (registry keys, service states, audit policy values). Which CIS resource provides this level of prescriptive detail?

Show answer & explanation

Correct answer: C - The CIS Benchmarks, which provide consensus-developed configuration guidance per platform

Question 9

A security manager needs to determine what should be measured for a given Safeguard, including the defined inputs, operations, and resulting metric calculations, in a way that is not tied to any particular vendor product. Which CIS resource is purpose-built for this?

Show answer & explanation

Correct answer: D - CIS Controls Assessment Specification (CAS)

Question 10

CIS Controls v8.1 introduced a change that aligns the framework with NIST Cybersecurity Framework 2.0. Which statement accurately describes what v8.1 changed?

Show answer & explanation

Correct answer: A - It added the Govern security function and left the Safeguard count at 153

The rest of the GCCC blueprint

The GCCC exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,052

The full bank has 1,042 more GCCC questions with explanations.

Continue in the free practice test →

View plans