
Certified Cybersecurity Operations Analyst
Domain 2Objective 2
Risk Management CCOA Practice Questions (Page 3)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
20%of the exam
Questions 11–15
- 11
A hospital's IT department has identified a critical vulnerability in its patient portal that could expose protected health information (PHI). The vulnerability is in a custom application that is integral to patient scheduling. The hospital has limited budget and must decide among the following options: (1) take the portal offline until a patch is developed, (2) implement a web application firewall (WAF) and monitor logs, (3) purchase cyber insurance, or (4) do nothing and accept the risk. The hospital's leadership is risk-averse and wants to minimize the chance of a breach, but also needs to maintain patient access to scheduling. Which strategy best balances these constraints?
Select an answer first - 12
A regional bank processes card payments and stores customer data. After a risk assessment, the bank identifies that a legacy payment application has a critical vulnerability that could allow remote code execution. The vendor no longer provides patches, and the application is essential to daily operations. The bank's leadership wants to continue using the application while minimizing risk. What is the most appropriate risk response strategy?
Select an answer first - 13
A risk analyst assigns a monetary value to the potential loss from a cyber attack and calculates the annualized loss expectancy. Which risk assessment method is being used?
Select an answer first - 14
A manufacturing company is conducting a risk assessment for its industrial control systems (ICS). The team has identified that a specific type of malware could exploit a known vulnerability in the ICS software. They are now determining the likelihood of this threat exploiting the vulnerability and the potential impact on production. Which step of the risk management process are they performing?
Select an answer first - 15
During a risk assessment, an analyst notes that a company's web server is running an outdated version of Apache with a known vulnerability. An attacker could exploit this vulnerability to gain unauthorized access. In this scenario, what is the threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.