Practice CCOA Securing Assets questions with full explanations on every answer.
Start practicing
Securing Assets — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are tasked with hardening an endpoint using the CIS Benchmark for Windows 10. You need to ensure that the 'Local Account Password Complexity' is enforced. Which GPO path should you navigate to?
2You are configuring Microsoft Defender for Endpoint (MDE) to restrict USB storage access on corporate-managed Windows endpoints. Which policy setting should you configure in the Microsoft Intune Endpoint Security portal to ensure only authorized hardware IDs are permitted while blocking all others?
3You are performing a credentialed vulnerability scan using Nessus Professional on a Linux server. The scan reports that the 'Remote Windows SMB' service is missing patches, but the target is Linux. What is the most likely cause of this discrepancy?
4You are managing access for a cloud-native application using AWS IAM. You need to ensure that an EC2 instance can only access a specific S3 bucket. What is the most secure way to implement this?
5While monitoring security logs in Splunk for your critical database server, you observe a spike in '401 Unauthorized' errors followed by a '200 OK' success from a known administrative account. How should you investigate this to confirm a potential credential stuffing attack?
6You are using Tenable.io to manage vulnerabilities across a hybrid environment. You notice that several endpoints are not appearing in the 'Asset Inventory' dashboard despite having the Nessus Agent installed. What is the first troubleshooting step you should take?
7You are implementing 'Just-in-Time' (JIT) access for Azure Virtual Machines using Microsoft Defender for Cloud. A developer complains they cannot request access to a VM. What is the most likely reason?
8You are conducting an asset inventory and discover a device communicating with a known malicious IP address. The device is a corporate laptop. What is the most immediate, effective containment action?
9You are configuring a Linux server and want to use 'iptables' to block all incoming traffic from a specific subnet (192.168.10.0/24). Which command is correct?
10During an audit, you need to classify assets based on their criticality. Which of the following is the best example of a 'High' classification for an asset?
11When setting up a new security monitoring tool, you need to define 'Critical Assets'. Which criteria should NOT be used to determine asset criticality?
12You are configuring AWS Security Groups for a web server. Which rule set follows the 'Principle of Least Privilege' best?
13You need to ensure that all endpoints in your organization have the 'CrowdStrike Falcon' agent running and are reporting correctly. Which dashboard should you use?
14You observe that a specific Windows service is running as 'SYSTEM' but is vulnerable to DLL hijacking. What is the most effective way to harden this service without disabling it?
15You are troubleshooting a failure in a 'Certificate-Based Authentication' setup for a VPN. The logs show 'Handshake Failure'. What tool should you use to verify the server's certificate chain status?
16A vulnerability report shows that your web application is susceptible to 'Clickjacking'. Which HTTP header should you implement to mitigate this?
17You are configuring a SIEM alert to trigger when a user account is locked out. Which Windows Event ID should your filter target?
18You are reviewing a list of vulnerabilities found by an automated scanner. Which type of vulnerability would be considered the most critical to remediate first?
19You notice a surge in outbound traffic from a workstation to a series of random external IP addresses. This suggests a potential botnet infection. What is the most appropriate forensic data to collect first?
20You are configuring an Endpoint Security policy to harden Windows 10 devices. Which TWO of the following settings are recommended as best practice to mitigate physical access risks?
21You are setting up a secure baseline for a new server. You need to ensure the operating system logs are sent to a centralized logging server. Which service should you configure?
22What is the primary purpose of an 'Endpoint Detection and Response' (EDR) solution?
23You are hardening a Linux server and want to disable all unused network ports. Which command would be best to identify listening ports and their associated processes?
24You are evaluating a third-party application's access requirements. Which THREE of the following are considered 'Least Privilege' implementations?
25You are auditing your cloud environment for 'Shadow IT'. Which TWO of the following methods are effective for identifying unauthorized assets?
26Your vulnerability management program requires prioritizing fixes based on exploitability. Which THREE of the following factors should be included in your risk score?
27Which TWO of the following are examples of good asset inventory management practices?
28You are configuring security monitoring for a database. Which THREE events should you definitely log to ensure compliance and detect malicious activity?
29You are hardening a web server. Which TWO of the following steps are critical for 'Endpoint Hardening' of the web service itself?
30Which THREE of the following are examples of 'Access Control' implementations?
31You are performing a vulnerability assessment on a server. Which TWO of the following indicators would suggest an asset is part of the 'Critical' category?
32You are analyzing logs to detect a 'Lateral Movement' attack. Which THREE of the following behaviors are common indicators?
The Securing Assets domain covers the key concepts tested in this area of the CCOA exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CCOA domains — no account required.
The Courseiva CCOA question bank contains 32 questions in the Securing Assets domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Assets domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included