Courseiva

CCOA · domain

Securing Assets

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Securing Assets practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

32 questions7 easy14 medium11 hard

Focused practice

Practice Securing Assets questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Securing Assets

Securing Assets questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Securing Assets exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Securing Assets questions (32)

Click any question to see the full explanation, or start a practice session above.

1

You are implementing 'Just-in-Time' (JIT) access for Azure Virtual Machines using Microsoft Defender for Cloud. A developer complains they cannot request access to a VM. What is the most likely reason?

Hard
2

You are configuring an Endpoint Security policy to harden Windows 10 devices. Which TWO of the following settings are recommended as best practice to mitigate physical access risks?

Medium
3

You observe that a specific Windows service is running as 'SYSTEM' but is vulnerable to DLL hijacking. What is the most effective way to harden this service without disabling it?

Hard
4

You are auditing your cloud environment for 'Shadow IT'. Which TWO of the following methods are effective for identifying unauthorized assets?

Medium
5

Your vulnerability management program requires prioritizing fixes based on exploitability. Which THREE of the following factors should be included in your risk score?

Hard
6

When setting up a new security monitoring tool, you need to define 'Critical Assets'. Which criteria should NOT be used to determine asset criticality?

Easy
7

You need to ensure that all endpoints in your organization have the 'CrowdStrike Falcon' agent running and are reporting correctly. Which dashboard should you use?

Medium
8

You are performing a vulnerability assessment on a server. Which TWO of the following indicators would suggest an asset is part of the 'Critical' category?

Medium
9

You are conducting an asset inventory and discover a device communicating with a known malicious IP address. The device is a corporate laptop. What is the most immediate, effective containment action?

Medium
10

Which TWO of the following are examples of good asset inventory management practices?

Easy
11

You are tasked with hardening an endpoint using the CIS Benchmark for Windows 10. You need to ensure that the 'Local Account Password Complexity' is enforced. Which GPO path should you navigate to?

Easy
12

Which THREE of the following are examples of 'Access Control' implementations?

Easy
13

You are troubleshooting a failure in a 'Certificate-Based Authentication' setup for a VPN. The logs show 'Handshake Failure'. What tool should you use to verify the server's certificate chain status?

Hard
14

While monitoring security logs in Splunk for your critical database server, you observe a spike in '401 Unauthorized' errors followed by a '200 OK' success from a known administrative account. How should you investigate this to confirm a potential credential stuffing attack?

Hard
15

You notice a surge in outbound traffic from a workstation to a series of random external IP addresses. This suggests a potential botnet infection. What is the most appropriate forensic data to collect first?

Medium
16

You are configuring AWS Security Groups for a web server. Which rule set follows the 'Principle of Least Privilege' best?

Medium
17

You are managing access for a cloud-native application using AWS IAM. You need to ensure that an EC2 instance can only access a specific S3 bucket. What is the most secure way to implement this?

Medium
18

You are using Tenable.io to manage vulnerabilities across a hybrid environment. You notice that several endpoints are not appearing in the 'Asset Inventory' dashboard despite having the Nessus Agent installed. What is the first troubleshooting step you should take?

Medium
19

What is the primary purpose of an 'Endpoint Detection and Response' (EDR) solution?

Easy
20

You are performing a credentialed vulnerability scan using Nessus Professional on a Linux server. The scan reports that the 'Remote Windows SMB' service is missing patches, but the target is Linux. What is the most likely cause of this discrepancy?

Hard
21

You are configuring a Linux server and want to use 'iptables' to block all incoming traffic from a specific subnet (192.168.10.0/24). Which command is correct?

Medium
22

You are evaluating a third-party application's access requirements. Which THREE of the following are considered 'Least Privilege' implementations?

Hard
23

During an audit, you need to classify assets based on their criticality. Which of the following is the best example of a 'High' classification for an asset?

Easy
24

A vulnerability report shows that your web application is susceptible to 'Clickjacking'. Which HTTP header should you implement to mitigate this?

Hard
25

You are configuring a SIEM alert to trigger when a user account is locked out. Which Windows Event ID should your filter target?

Medium
26

You are configuring security monitoring for a database. Which THREE events should you definitely log to ensure compliance and detect malicious activity?

Medium
27

You are hardening a web server. Which TWO of the following steps are critical for 'Endpoint Hardening' of the web service itself?

Hard
28

You are configuring Microsoft Defender for Endpoint (MDE) to restrict USB storage access on corporate-managed Windows endpoints. Which policy setting should you configure in the Microsoft Intune Endpoint Security portal to ensure only authorized hardware IDs are permitted while blocking all others?

Medium
29

You are hardening a Linux server and want to disable all unused network ports. Which command would be best to identify listening ports and their associated processes?

Hard
30

You are reviewing a list of vulnerabilities found by an automated scanner. Which type of vulnerability would be considered the most critical to remediate first?

Easy
31

You are analyzing logs to detect a 'Lateral Movement' attack. Which THREE of the following behaviors are common indicators?

Hard
32

You are setting up a secure baseline for a new server. You need to ensure the operating system logs are sent to a centralized logging server. Which service should you configure?

Medium

Frequently asked questions

What does the Securing Assets domain cover on the CCOA exam?
Securing Assets questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 32 Securing Assets questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Securing Assets questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-ccoa ISACA-CCOA securing assets Practice Questions