Free CCOA Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Isaca CCOA
Q: 1
Which layer of the TCP/IP stack promotes the reliable transmission of data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
SIMULATION
For this question you must log into Greenbone Vulnerability Manager using Firefox. The URL is:
https://10.10.55.4:9392 and credentials are:
Username: admin
Password: Secure-gvm!
A colleague performed a vulnerability scan but did not review prior to leaving for a family
emergency. It has been determined that a threat actor is using CVE-2021-22145 in the wild. What is
the host IP of the machine that is vulnerable to this CVE?
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Which of the following is a PRIMARY risk that can be introduced through the use of a site-to-site
virtual private network (VPN) with a service provider?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
An organization was breached via a web application attack to a database in which user inputs were
not validated. This can BEST be described as which type of attack?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of the following is the MOST effective approach for tracking vulnerabilities in an organization's
systems and applications?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A small organization has identified a potential risk associated with its outdated backup system and
has decided to implement a new cloud-based real-time backup system to reduce the likelihood of
data loss. Which of the following risk responses has the organization chosen?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Which of the following BEST enables an organization to identify potential security threats by
monitoring and analyzing network traffic for unusual activity?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A penetration tester has been hired and given access to all code, diagrams, and documentation.
Which type of testing is being conducted?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Which type of access control can be modified by a user or data owner?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
In which cloud service model are clients responsible for regularly updating the operating system?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
An organization moving its payment card system into a separate location on its network (or security
reasons is an example of network:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Multi-factor authentication (MFA) BEST protects against which of the following attack vectors?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Cyber threat intelligence is MOST important for:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Management has requested an additional layer of remote access control to protect a critical
database that is hosted online. Which of the following would 8EST provide this protection?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Which of the following Is a control message associated with the Internet Control Message Protocol
(ICMP)?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Which of the following is the GREATEST risk resulting from a Domain Name System (DNS) cache
poisoning attack?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Which of the following is MOST likely to result from a poorly enforced bring your own device (8YOD)
policy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Which of the following MOST effectively minimizes the impact of a control failure?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Which of the following is the PRIMARY purpose of load balancers in cloud networking?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Exposing the session identifier in a URL is an example of which web application-specific risk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20