
Certified Cybersecurity Operations Analyst
Domain 5Objective 2
Controls and Techniques CCOA Practice Questions (Page 7)
Part of the Domain 5: Securing Assets domain, which accounts for 11% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
12concepts
11%of the exam
Questions 31–35
- 31
A hospital wants to ensure that only nurses and doctors can access patient records, based on their job function. Which access control model is most appropriate?
Select an answer first - 32
What is the primary benefit of multi-factor authentication (MFA) over single-factor authentication?
Select an answer first - 33
A financial analyst needs access to customer account data to prepare reports, but should not be able to modify the data or view other employees' salaries. Which authorization principle should the access control system enforce?
Select an answer first - 34
A company has a network with a public-facing web server and an internal database. The security team wants to ensure that if the web server is compromised, the attacker cannot easily access the database. Which network security control should they implement?
Select an answer first - 35
In which access control model does the owner of a resource decide who can access it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.