
Certified Cybersecurity Operations Analyst
Domain 5Objective 3
Identity and Access Management CCOA Practice Questions (Page 3)
Part of the Domain 5: Securing Assets domain, which accounts for 11% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
6concepts
11%of the exam
Questions 11–15
- 11
A security analyst is reviewing the IAM controls for a critical application. The analyst wants to ensure that the application enforces accountability. Which of the following controls are essential for accountability? (Select all that apply.)
Select an answer first - 12
In the context of IAM, which component is responsible for verifying that a user is who they claim to be?
Select an answer first - 13
A large enterprise is migrating from a legacy system where each department managed its own file shares and permissions. The security team wants to enforce least privilege across the organization. They are considering implementing RBAC. However, a department manager argues that RBAC is too rigid because some employees need temporary access to resources outside their role for specific projects. Which approach should the security team take to address this concern while still maintaining least privilege?
Select an answer first - 14
A company is considering replacing password-based authentication with a biometric system for all employees. The security team is concerned about the risk of biometric data being stolen and the inability to change biometric traits if compromised. Which additional control should they implement to mitigate these concerns?
Select an answer first - 15
A company is preparing for a compliance audit. The auditor requires evidence that user access rights are reviewed regularly and that any inappropriate access is corrected. The identity team currently performs access reviews manually using spreadsheets, which is time-consuming and error-prone. The team wants to automate the process but is concerned about the cost of implementing an identity governance tool. Which approach should they take to satisfy the auditor while managing costs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.