Courseiva

CCOA · domain

Cybersecurity Principles And Risk

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Cybersecurity Principles And Risk practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

29 questions10 easy9 medium10 hard

Focused practice

Practice Cybersecurity Principles And Risk questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cybersecurity Principles And Risk

Cybersecurity Principles And Risk questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cybersecurity Principles And Risk exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Cybersecurity Principles And Risk questions (29)

Click any question to see the full explanation, or start a practice session above.

1

When designing a defense-in-depth strategy, which layer should be addressed first as the primary boundary between internal and external networks?

Medium
2

An analyst is setting up a new firewall. The policy dictates that all traffic is blocked unless explicitly permitted. What principle is being followed?

Medium
3

An analyst is assessing the 'Availability' of a database. Which scenario represents a threat to availability?

Medium
4

Which TWO of the following are considered 'Technical' controls?

Hard
5

Which TWO of the following are core components of the CIA Triad?

Easy
6

You are implementing ISO 27001 Annex A controls. Which control category would contain requirements for physical access to the server room?

Hard
7

Which document outlines the formal commitment of top management to support information security objectives?

Easy
8

You are reviewing a cloud architecture against the NIST 800-53 control catalog. Which control family would you reference for incidents involving unauthorized data exfiltration?

Hard
9

Which TWO of the following are examples of 'Detection' capabilities in the NIST CSF?

Easy
10

Which security framework is most commonly used by US federal agencies to manage security controls?

Easy
11

You are performing STRIDE threat modeling on a new web application. A developer asks how to mitigate a 'Tampering' threat identified during the design phase. Which control is most effective?

Hard
12

You are performing a quantitative risk assessment. The SLE (Single Loss Expectancy) is $10,000, and the ARO (Annualized Rate of Occurrence) is 0.5. What is the ALE (Annualized Loss Expectancy)?

Hard
13

A security analyst is mapping organizational assets to the NIST Cybersecurity Framework. Which category is specifically responsible for maintaining the resilience of critical infrastructure?

Easy
14

Which THREE items are typically included in a formal Risk Register?

Medium
15

Which TWO elements should be included when performing threat modeling using the STRIDE methodology?

Hard
16

You are utilizing the MITRE ATT&CK framework to document an incident. Which object represents the 'what' of the attack, such as the specific software or tool used?

Hard
17

A security analyst is reviewing access logs and notices a user with 'Administrator' rights performing daily data entry. Which principle is being violated?

Medium
18

In a FAIR (Factor Analysis of Information Risk) model, what is the 'Loss Event Frequency' composed of?

Hard
19

What is the primary objective of a 'Business Impact Analysis' (BIA)?

Easy
20

Which TWO of the following are primary functions of an Information Security Governance program?

Medium
21

During threat modeling, you identify that an adversary could impersonate a service account. Which control is most effective against this?

Hard
22

Which role is primarily responsible for classifying data based on its value and sensitivity to the organization?

Easy
23

An organization is updating its BCP plan. Which step in the risk assessment process should occur immediately after identifying the critical assets?

Medium
24

Which THREE controls are considered effective 'Administrative' controls according to the NIST framework?

Hard
25

During a risk assessment using ISO 27001, you identify an unpatched vulnerability in an edge router. Management refuses to apply the patch due to legacy software dependencies. Which risk treatment option are they exercising?

Medium
26

Which THREE actions are essential to the 'Identify' function of the NIST CSF?

Medium
27

Which type of risk assessment approach uses descriptive scales like 'High', 'Medium', and 'Low'?

Easy
28

You are tasked with ensuring the 'Confidentiality' of sensitive data in transit. Which mechanism best satisfies this security principle?

Easy
29

Which THREE factors are commonly used to calculate risk in a basic qualitative model?

Easy

Frequently asked questions

What does the Cybersecurity Principles And Risk domain cover on the CCOA exam?
Cybersecurity Principles And Risk questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 29 Cybersecurity Principles And Risk questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cybersecurity Principles And Risk questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Cybersecurity Principles And Risk Practice Questions