Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following is MOST likely to outline and communicate the organization's vulnerability management program?
A policy is the most likely document to outline and communicate an organization's vulnerability management program.
Purpose: Policies establish high-level principles and guidelines for managing vulnerabilities.
Scope: Typically includes roles, responsibilities, frequency of assessments, and remediation processes.
Communication: Policies are formal documents that are communicated across the organization to ensure consistent adherence.
Governance: Ensures that vulnerability management practices align with organizational risk management objectives.
Incorrect Options:
A . Vulnerability assessment report: Details specific findings, not the overarching management program.
B . Guideline: Provides suggestions rather than mandates; less formal than a policy.
D . Control framework: A broader structure that includes policies but does not specifically outline the vulnerability management program.
Exact Extract from CCOA Official Review Manual, 1st Edition:
Refer to Chapter 5, Section 'Vulnerability Management Program,' Subsection 'Policy Development' - A comprehensive policy defines the entire vulnerability management approach.
Which type of access control can be modified by a user or data owner?
Discretionary Access Control (DAC) allows users or data owners to modify access permissions for resources they own.
Owner-Based Permissions: The resource owner decides who can access or modify the resource.
Flexibility: Users can grant, revoke, or change permissions as needed.
Common Implementation: File systems where owners set permissions for files and directories.
Risk: Misconfigurations can lead to unauthorized access if not properly managed.
Other options analysis:
A . Mandatory Access Control (MAC): Permissions are enforced by the system, not the user.
B . Role-Based Access Control (RBAC): Access is based on roles, not user discretion.
D . Rule-Based Access Control: Permissions are determined by predefined rules, not user control.
CCOA Official Review Manual, 1st Edition Reference:
Chapter 7: Access Control Models: Clearly distinguishes DAC from other access control methods.
Chapter 9: Secure Access Management: Explains how DAC is implemented and managed.
In which cloud service model are clients responsible for regularly updating the operating system?
In the IaaS (Infrastructure as a Service) model, clients are responsible for managing and updating the operating system because:
Client Responsibility: The provider supplies virtualized computing resources (e.g., VMs), but OS maintenance remains with the client.
Flexibility: Users can install, configure, and update OSs according to their needs.
Examples: AWS EC2, Microsoft Azure VMs.
Compared to Other Models:
SaaS: The provider manages the entire stack, including the OS.
DBaaS: Manages databases without requiring OS maintenance.
PaaS: The platform is managed, leaving no need for direct OS updates.
CCOA Official Review Manual, 1st Edition Reference:
Chapter 10: Cloud Security and IaaS Management: Discusses client responsibilities in IaaS environments.
Chapter 9: Cloud Deployment Models: Explains how IaaS differs from SaaS and PaaS.
SIMULATION
For this question you must log into Greenbone Vulnerability Manager using Firefox. The URL is: https://10.10.55.4:9392 and credentials are:
Username: admin
Password: Secure-gvm!
A colleague performed a vulnerability scan but did not review prior to leaving for a family emergency. It has been determined that a threat actor is using CVE-2021-22145 in the wild. What is the host IP of the machine that is vulnerable to this CVE?
To determine the host IP of the machine vulnerable to CVE-2021-22145 using Greenbone Vulnerability Manager (GVM), follow these detailed steps:
Step 1: Access Greenbone Vulnerability Manager
Open Firefox on your system.
Go to the GVM login page:
URL: https://10.10.55.4:9392
Enter the credentials:
Username: admin
Password: Secure-gvm!
Click Login to access the dashboard.
Step 2: Navigate to Scan Reports
Once logged in, locate the 'Scans' menu on the left panel.
Click on 'Reports' under the 'Scans' section to view the list of completed vulnerability scans.
Step 3: Identify the Most Recent Scan
Check the date and time of the last completed scan, as your colleague likely used the latest one.
Click on the Report Name or Date to open the detailed scan results.
Step 4: Filter for CVE-2021-22145
In the report view, locate the 'Search' or 'Filter' box at the top.
Enter the CVE identifier:
CVE-2021-22145
Press Enter to filter the vulnerabilities.
Step 5: Analyze the Results
The system will display any host(s) affected by CVE-2021-22145.
The details will typically include:
Host IP Address
Vulnerability Name
Severity Level
Vulnerability Details
Example Display:
Host IP Vulnerability ID CVE Severity
192.168.1.100 SomeVulnName CVE-2021-22145 High
Step 6: Verify the Vulnerability
Click on the host IP to see the detailed vulnerability description.
Check for the following:
Exploitability: Proof that the vulnerability can be actively exploited.
Description and Impact: Details about the vulnerability and its potential impact.
Fixes/Recommendations: Suggested mitigations or patches.
Step 7: Note the Vulnerable Host IP
The IP address that appears in the filtered list is the vulnerable machine.
Example Answe r:
The host IP of the machine vulnerable to CVE-2021-22145 is: 192.168.1.100
Step 8: Take Immediate Actions
Isolate the affected machine to prevent exploitation.
Patch or update the software affected by CVE-2021-22145.
Perform a quick re-scan to ensure that the vulnerability has been mitigated.
Step 9: Generate a Report for Documentation
Export the filtered scan results as a PDF or HTML from the GVM.
Include:
Host IP
CVE ID
Severity and Risk Level
Remediation Steps
Background on CVE-2021-22145:
This CVE is related to a vulnerability in certain software, often associated with improper access control or authentication bypass.
Attackers can exploit this to gain unauthorized access or escalate privileges.
Which of the following is the MOST important component of the asset decommissioning process from a data risk perspective?
The most important component of asset decommissioning from a data risk perspective is the secure destruction of data on the asset.
Data Sanitization: Ensures that all sensitive information is irretrievably erased before disposal or repurposing.
Techniques: Physical destruction, secure wiping, or degaussing depending on the storage medium.
Risk Mitigation: Prevents data leakage if the asset falls into unauthorized hands.
Incorrect Options:
A . Informing the data owner: Important but secondary to data destruction.
C . Updating the CMDB: Administrative task, not directly related to data risk.
D . Removing monitoring: Important for system management but not the primary risk factor.
Exact Extract from CCOA Official Review Manual, 1st Edition:
Refer to Chapter 9, Section 'Asset Decommissioning,' Subsection 'Data Sanitization Best Practices' - Data destruction is the most critical step to mitigate risks.
139 questions covering all exam domains, starting from $20
Exam domains verified against: Official Isaca CCOA exam guide, last checked September 2026.
Covers foundational technologies and principles that form the backbone of cybersecurity operations. Candidates learn key components of computer and cloud networking, databases, virtualization, containerization, command-line interfaces, and programming concepts used in security monitoring and analysis.
Sample question from this domain above: Q2
Addresses core cybersecurity principles and risk management strategies essential for security analysts. This domain ensures professionals understand governance, risk frameworks, and how security aligns with business objectives and decision-making.
Sample question from this domain above: Q4
Examines the tactics, techniques, and procedures used by adversaries to compromise systems. Analysts learn to recognize attack patterns and develop critical thinking skills for identifying threats before they cause damage.
Focuses on the core work of security operations centres: detecting security incidents and responding appropriately. This domain carries the heaviest weighting and tests hands-on ability to analyze alerts, investigate incidents, and take containment action.
Covers methods and strategies used to secure organizational assets. Candidates learn practical approaches to implementing controls that protect systems, data, and infrastructure from compromise.
Sample question from this domain above: Q5
Common questions about the exam itself