CCOA · domain
Securing Assets
Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Securing Assets practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Securing Assets questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Securing Assets
Securing Assets questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Securing Assets exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Securing Assets questions (32)
Click any question to see the full explanation, or start a practice session above.
You are implementing 'Just-in-Time' (JIT) access for Azure Virtual Machines using Microsoft Defender for Cloud. A developer complains they cannot request access to a VM. What is the most likely reason?
Hard2You are configuring an Endpoint Security policy to harden Windows 10 devices. Which TWO of the following settings are recommended as best practice to mitigate physical access risks?
Medium3You observe that a specific Windows service is running as 'SYSTEM' but is vulnerable to DLL hijacking. What is the most effective way to harden this service without disabling it?
Hard4You are auditing your cloud environment for 'Shadow IT'. Which TWO of the following methods are effective for identifying unauthorized assets?
Medium5Your vulnerability management program requires prioritizing fixes based on exploitability. Which THREE of the following factors should be included in your risk score?
Hard6When setting up a new security monitoring tool, you need to define 'Critical Assets'. Which criteria should NOT be used to determine asset criticality?
Easy7You need to ensure that all endpoints in your organization have the 'CrowdStrike Falcon' agent running and are reporting correctly. Which dashboard should you use?
Medium8You are performing a vulnerability assessment on a server. Which TWO of the following indicators would suggest an asset is part of the 'Critical' category?
Medium9You are conducting an asset inventory and discover a device communicating with a known malicious IP address. The device is a corporate laptop. What is the most immediate, effective containment action?
Medium10Which TWO of the following are examples of good asset inventory management practices?
Easy11You are tasked with hardening an endpoint using the CIS Benchmark for Windows 10. You need to ensure that the 'Local Account Password Complexity' is enforced. Which GPO path should you navigate to?
Easy12Which THREE of the following are examples of 'Access Control' implementations?
Easy13You are troubleshooting a failure in a 'Certificate-Based Authentication' setup for a VPN. The logs show 'Handshake Failure'. What tool should you use to verify the server's certificate chain status?
Hard14While monitoring security logs in Splunk for your critical database server, you observe a spike in '401 Unauthorized' errors followed by a '200 OK' success from a known administrative account. How should you investigate this to confirm a potential credential stuffing attack?
Hard15You notice a surge in outbound traffic from a workstation to a series of random external IP addresses. This suggests a potential botnet infection. What is the most appropriate forensic data to collect first?
Medium16You are configuring AWS Security Groups for a web server. Which rule set follows the 'Principle of Least Privilege' best?
Medium17You are managing access for a cloud-native application using AWS IAM. You need to ensure that an EC2 instance can only access a specific S3 bucket. What is the most secure way to implement this?
Medium18You are using Tenable.io to manage vulnerabilities across a hybrid environment. You notice that several endpoints are not appearing in the 'Asset Inventory' dashboard despite having the Nessus Agent installed. What is the first troubleshooting step you should take?
Medium19What is the primary purpose of an 'Endpoint Detection and Response' (EDR) solution?
Easy20You are performing a credentialed vulnerability scan using Nessus Professional on a Linux server. The scan reports that the 'Remote Windows SMB' service is missing patches, but the target is Linux. What is the most likely cause of this discrepancy?
Hard21You are configuring a Linux server and want to use 'iptables' to block all incoming traffic from a specific subnet (192.168.10.0/24). Which command is correct?
Medium22You are evaluating a third-party application's access requirements. Which THREE of the following are considered 'Least Privilege' implementations?
Hard23During an audit, you need to classify assets based on their criticality. Which of the following is the best example of a 'High' classification for an asset?
Easy24A vulnerability report shows that your web application is susceptible to 'Clickjacking'. Which HTTP header should you implement to mitigate this?
Hard25You are configuring a SIEM alert to trigger when a user account is locked out. Which Windows Event ID should your filter target?
Medium26You are configuring security monitoring for a database. Which THREE events should you definitely log to ensure compliance and detect malicious activity?
Medium27You are hardening a web server. Which TWO of the following steps are critical for 'Endpoint Hardening' of the web service itself?
Hard28You are configuring Microsoft Defender for Endpoint (MDE) to restrict USB storage access on corporate-managed Windows endpoints. Which policy setting should you configure in the Microsoft Intune Endpoint Security portal to ensure only authorized hardware IDs are permitted while blocking all others?
Medium29You are hardening a Linux server and want to disable all unused network ports. Which command would be best to identify listening ports and their associated processes?
Hard30You are reviewing a list of vulnerabilities found by an automated scanner. Which type of vulnerability would be considered the most critical to remediate first?
Easy31You are analyzing logs to detect a 'Lateral Movement' attack. Which THREE of the following behaviors are common indicators?
Hard32You are setting up a secure baseline for a new server. You need to ensure the operating system logs are sent to a centralized logging server. Which service should you configure?
MediumOther domains
All CCOA exam domains
Frequently asked questions
- What does the Securing Assets domain cover on the CCOA exam?
- Securing Assets questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 32 Securing Assets questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Securing Assets questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.