
Certified Cybersecurity Operations Analyst
Domain 5Objective 6
Vulnerability Identification CCOA Practice Questions (Page 6)
Part of the Domain 5: Securing Assets domain, which accounts for 11% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
11%of the exam
Questions 26–30
- 26
A vulnerability scan of a corporate network identified the following findings: (1) a critical remote code execution vulnerability in a legacy web server that is isolated from the internet and scheduled for decommissioning in two months; (2) a high-severity SQL injection flaw in a public-facing customer portal that has no known exploit in the wild; (3) a medium-severity misconfiguration on an internal file server that stores sensitive HR data. The analyst must prioritize remediation. Which vulnerability should be addressed first?
Select an answer first - 27
A security analyst is building a vulnerability management program and needs a reliable source of vulnerability information to feed into the scanning and prioritization process. The analyst wants a standardized, publicly accessible database that assigns unique identifiers and severity scores. Which source should the analyst use?
Select an answer first - 28
A vulnerability scan identified a critical vulnerability in a database server that stores customer payment information. The vulnerability is not currently being exploited, but a proof-of-concept exploit has been published. The database server is internal and not directly accessible from the internet. The analyst must decide on a remediation priority. What should the analyst do?
Select an answer first - 29
A security analyst is researching a newly disclosed vulnerability in a widely used application. The analyst needs to understand the technical details, the affected versions, and any available mitigations. Which source would provide the most authoritative and structured information?
Select an answer first - 30
Which of the following is an example of a vendor advisory that provides vulnerability information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCOA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.