Practice CCOA Cybersecurity Principles And Risk questions with full explanations on every answer.
Start practicing
Cybersecurity Principles And Risk — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization is updating its BCP plan. Which step in the risk assessment process should occur immediately after identifying the critical assets?
2During a risk assessment using ISO 27001, you identify an unpatched vulnerability in an edge router. Management refuses to apply the patch due to legacy software dependencies. Which risk treatment option are they exercising?
3You are performing STRIDE threat modeling on a new web application. A developer asks how to mitigate a 'Tampering' threat identified during the design phase. Which control is most effective?
4You are tasked with ensuring the 'Confidentiality' of sensitive data in transit. Which mechanism best satisfies this security principle?
5You are reviewing a cloud architecture against the NIST 800-53 control catalog. Which control family would you reference for incidents involving unauthorized data exfiltration?
6An analyst is assessing the 'Availability' of a database. Which scenario represents a threat to availability?
7A security analyst is mapping organizational assets to the NIST Cybersecurity Framework. Which category is specifically responsible for maintaining the resilience of critical infrastructure?
8Which document outlines the formal commitment of top management to support information security objectives?
9What is the primary objective of a 'Business Impact Analysis' (BIA)?
10In a FAIR (Factor Analysis of Information Risk) model, what is the 'Loss Event Frequency' composed of?
11When designing a defense-in-depth strategy, which layer should be addressed first as the primary boundary between internal and external networks?
12Which role is primarily responsible for classifying data based on its value and sensitivity to the organization?
13An analyst is setting up a new firewall. The policy dictates that all traffic is blocked unless explicitly permitted. What principle is being followed?
14You are implementing ISO 27001 Annex A controls. Which control category would contain requirements for physical access to the server room?
15You are performing a quantitative risk assessment. The SLE (Single Loss Expectancy) is $10,000, and the ARO (Annualized Rate of Occurrence) is 0.5. What is the ALE (Annualized Loss Expectancy)?
16Which security framework is most commonly used by US federal agencies to manage security controls?
17Which TWO of the following are core components of the CIA Triad?
18A security analyst is reviewing access logs and notices a user with 'Administrator' rights performing daily data entry. Which principle is being violated?
19Which THREE items are typically included in a formal Risk Register?
20During threat modeling, you identify that an adversary could impersonate a service account. Which control is most effective against this?
21Which type of risk assessment approach uses descriptive scales like 'High', 'Medium', and 'Low'?
22You are utilizing the MITRE ATT&CK framework to document an incident. Which object represents the 'what' of the attack, such as the specific software or tool used?
23Which TWO elements should be included when performing threat modeling using the STRIDE methodology?
24Which THREE factors are commonly used to calculate risk in a basic qualitative model?
25Which TWO of the following are primary functions of an Information Security Governance program?
26Which TWO of the following are examples of 'Detection' capabilities in the NIST CSF?
27Which THREE actions are essential to the 'Identify' function of the NIST CSF?
28Which TWO of the following are considered 'Technical' controls?
29Which THREE controls are considered effective 'Administrative' controls according to the NIST framework?
The Cybersecurity Principles And Risk domain covers the key concepts tested in this area of the CCOA exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CCOA domains — no account required.
The Courseiva CCOA question bank contains 29 questions in the Cybersecurity Principles And Risk domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cybersecurity Principles And Risk domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included