
Certified Cybersecurity Operations Analyst
Domain 2Objective 1
Cybersecurity Governance CCOA Practice Questions (Page 7)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
9concepts
20%of the exam
Questions 31–33
- 31
A company has a security incident that resulted in a data breach. The board wants to know who is accountable. The CISO says the security analyst who failed to act on an alert is responsible. The analyst says they were not trained on the new alert system. The manager says the analyst should have escalated. Who is ultimately accountable to the board?
Select an answer first - 32
Why are clear reporting lines important in cybersecurity governance?
Select an answer first - 33
A company is preparing for a SOC 2 audit. The audit will assess the company's controls related to security, availability, and confidentiality. What is the primary role of the auditor in this process?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCOA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.