
Certified Cybersecurity Operations Analyst
Domain 2Objective 4
Risk by Domain CCOA Practice Questions (Page 2)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
20%of the exam
Questions 6–10
- 6
What is software provenance in the context of supply chain risk?
Select an answer first - 7
A financial application stores customer transaction history. During a routine audit, the security team finds that the application logs contain full credit card numbers in plaintext, and these logs are accessible to all developers. Which data risk type is MOST directly increased by this practice?
Select an answer first - 8
A development team is building a new customer portal. The team frequently copies code snippets from public forums and integrates them into the application without review. Which application risk source is MOST directly introduced by this practice?
Select an answer first - 9
A web application allows users to search for products. The search functionality takes user input and directly includes it in a database query without sanitization. An attacker submits a specially crafted search term that modifies the query to return all user records. Which web application risk is MOST directly exploited?
Select an answer first - 10
Which of the following is a web application risk associated with injection attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.