
Certified Cybersecurity Operations Analyst
Domain 2Objective 3
Cybersecurity Architecture CCOA Practice Questions (Page 4)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
14concepts
20%of the exam
Questions 16–20
- 16
In the MITRE ATT&CK framework, what is a 'tactic'?
Select an answer first - 17
In the Zachman Framework, which column addresses the 'who' perspective of an enterprise architecture?
Select an answer first - 18
Which concept in the Clark-Wilson model ensures that a single user cannot perform all steps of a critical transaction alone?
Select an answer first - 19
A security team is analyzing a recent ransomware attack. They want to identify where they could have disrupted the attack early in the lifecycle. The attack involved a phishing email, exploitation of a vulnerability, installation of malware, and then encryption of files. Which stage of the Cyber Kill Chain should they focus on to prevent the initial compromise?
Select an answer first - 20
In the SABSA framework, which layer is responsible for defining the security strategy and architecture at the highest level, aligned with business strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.