
Certified Cybersecurity Operations Analyst
Domain 2Objective 2
Risk Management CCOA Practice Questions (Page 2)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
20%of the exam
Questions 6–10
- 6
A security analyst is explaining risk concepts to a new team member. The analyst says, 'The risk of a data breach is high because the likelihood of an attack is high and the impact on our reputation would be severe.' In this statement, what does 'likelihood' refer to?
Select an answer first - 7
A security analyst is explaining the concept of risk to a new employee. The analyst says, 'The risk of a data breach is high because the likelihood of an attack is high and the impact on our reputation would be severe.' In this statement, what does 'impact' refer to?
Select an answer first - 8
Which term describes a weakness in a system that could be exploited by a threat actor?
Select an answer first - 9
A risk assessment team rates the likelihood of a data breach as 'high' and the impact as 'moderate' based on expert judgment. Which risk assessment method are they using?
Select an answer first - 10
In the risk management process, which step involves determining the potential impact and likelihood of identified risks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.