
Certified Cybersecurity Operations Analyst
Domain 2Objective 4
Risk by Domain CCOA Practice Questions (Page 3)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
20%of the exam
Questions 11–15
- 11
Which phase of the data lifecycle is most associated with the risk of data being improperly disposed of?
Select an answer first - 12
A company deploys a web application to a public cloud. The application uses an object storage service to store user-uploaded documents. The security team discovers that the storage bucket is configured to allow public read access. Which cloud-specific risk is MOST directly exemplified?
Select an answer first - 13
A security analyst discovers that an attacker has been using a compromised service account to move laterally across the network over several weeks. The account had permissions to access multiple servers. The analyst needs to recommend a control that would MOST effectively limit the impact of similar compromises in the future, while minimizing operational disruption. Which recommendation should the analyst make?
Select an answer first - 14
A company's network uses a flat design where all servers and workstations are on the same subnet. A malware infection on one workstation spreads quickly to other systems. Which network risk factor is MOST directly contributing to the rapid spread?
Select an answer first - 15
In the cloud shared responsibility model, which of the following is typically the customer's responsibility?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.