IIBA-CCA · IIBA · Updated August 2026
IIBA-CCA practice questions
Original & expert-reviewed · explanation for every option · no dumps
Practise IIBA-CCA with original, expert-reviewed questions — each with an explanation for every option, linked to the source, across the full exam blueprint. No dumps, no ads, 6 free to start.
What makes these different from dumps
📚 An explanation for every option
Not just the right answer — why each wrong option is wrong, linked to the source. Wrong answers teach the most.
⏱️ Real-format timed mocks
Sit full 75-question, 120-minute exams and get a readiness report by area — know when you're ready.
↻ Spaced-repetition error log
Every miss comes back on a 1 → 3 → 7 → 16-day schedule, so the fixes actually stick.
🔖 Original & reviewed
Every question is written to test the concepts and reviewed before it ships — never copied or leaked “dumps”.
Try 10 real IIBA-CCA questions — free, no sign-up
A representative slice of the bank: every competency areas, mixed difficulty (hard ones included). Answers are one tap away — no email wall.
1/10 · Cybersecurity Foundations
A business analyst is documenting requirements for a new patient portal. The compliance officer states that under no circumstances may a patient's lab results be disclosed to anyone other than the patient and their authorized clinicians. Which element of the CIA triad does this requirement primarily protect?
AIntegrity
BAvailability
CNon-repudiation
DConfidentiality
Show answer & explanation
D is correct. The CIA triad is the foundation of information security. Confidentiality limits information access to authorized parties, integrity protects against improper modification, and availability ensures timely access for authorized users. A rule that data may only be disclosed to specific authorized people is a confidentiality control. A BA must correctly classify such requirements so that appropriate controls (e.g., access controls, encryption) are specified.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
2/10 · Cybersecurity Risk Management
A business analyst supporting a cybersecurity initiative is documenting the inputs needed to determine where the organization is exposed. The team agrees that risk can only exist where a threat is able to act against a weakness in something of value. Which combination of elements must be present together for a cybersecurity risk to exist?
AAn asset of value, a threat that can exploit it, and a vulnerability the threat can act upon
BA likelihood rating, an impact rating, and a calculated risk exposure value
CA documented control, a residual risk score, and an approved risk owner
DA compliance requirement, an audit finding, and a remediation deadline
Show answer & explanation
A is correct. The foundational model used throughout cybersecurity risk identification is the asset–threat–vulnerability relationship. A threat is a potential cause of harm; a vulnerability is a weakness that the threat can exploit; an asset is the thing of value at stake. Only when all three are present can a risk event occur, which is why the BA gathers and links these three elements before any analysis, scoring, or treatment begins.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
3/10 · Business Analysis Practices in Cybersecurity
A cybersecurity program is launching, and leadership wants someone to translate the organization's security and compliance objectives into clearly defined requirements that the technical security team can implement. Which contribution best describes the primary value a business analyst brings to a cybersecurity initiative?
AApproving the final security architecture and accepting residual risk on behalf of the organization
BBridging business, security, and technical stakeholders by eliciting needs and defining requirements that align security solutions with business objectives
CPerforming penetration tests to uncover exploitable vulnerabilities in production systems
DConfiguring firewalls, intrusion detection systems, and endpoint protection tools to enforce the security policy
Show answer & explanation
B is correct. The business analyst's distinctive contribution in cybersecurity is connecting business, security, and technical perspectives. By eliciting needs and defining requirements that map security solutions to business objectives, the BA ensures the right problem is solved and that security investments deliver business value. Implementation, testing, and risk acceptance belong to other roles.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
4/10 · Compliance and Governance
A new business analyst on a security program is asked to explain the difference between governance and compliance to a project sponsor. Which statement most accurately describes how the two relate within a cybersecurity context?
AGovernance applies only to publicly traded companies, while compliance applies only to government agencies.
BGovernance establishes the framework of policies, accountability, and decision rights that direct security; compliance is the act of conforming to those policies and to external laws, regulations, and standards.
CGovernance and compliance are interchangeable terms for the same audit activity performed at the end of a project.
DCompliance defines the organization's risk appetite and decision rights, while governance only checks regulatory checklists.
Show answer & explanation
B is correct. Governance is the system of direction, accountability, and decision rights that steers security activity, whereas compliance is the demonstrable conformance to internal policies and external laws, regulations, and standards. A cybersecurity BA must keep these separate because they produce different work products (e.g., policy/charter artifacts vs. evidence and control mappings).
↗ IIBA-CCA body of knowledge — Compliance and Governance
5/10 · Cybersecurity Foundations
While supporting a risk assessment, a business analyst needs to clearly distinguish core risk terminology for the project glossary. Which definition correctly describes a 'vulnerability' in cybersecurity terms?
AThe probability of a threat exploiting a weakness combined with the resulting impact
BA weakness in a system, process, or control that could be exploited to cause harm
CAnything of value to the organization that needs protection
DAny potential event or actor that could cause harm to an asset
Show answer & explanation
B is correct. In cybersecurity, a threat is a potential cause of harm, a vulnerability is a weakness that the threat can exploit, an asset is what is being protected, and risk is the combination of the likelihood of exploitation and the resulting impact. A BA must use these terms consistently so that stakeholders share a common understanding when defining requirements and controls.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
6/10 · Cybersecurity Risk Management
A BA is facilitating a risk workshop for a new customer-facing web portal. Subject matter experts rate one identified risk as having a high probability of occurring and a severe effect on the business if it does. Limited historical data is available, so the team uses descriptive bands such as Low, Medium, and High rather than dollar figures. What type of risk analysis is the team performing, and what is its primary output for this risk?
ARoot cause analysis, producing the underlying source of the vulnerability
BQuantitative analysis, producing an annualized loss expectancy in monetary terms
CQualitative analysis, producing a relative risk rating from combined likelihood and impact
DControl gap analysis, producing a list of missing safeguards
Show answer & explanation
C is correct. Risk analysis can be qualitative, semi-quantitative, or quantitative. Qualitative analysis combines likelihood and impact using descriptive scales (e.g., Low/Medium/High) to yield a relative risk rating, and is appropriate when reliable numeric data is unavailable or when speed and shared understanding matter more than precision. Quantitative analysis, by contrast, expresses risk in numeric or monetary terms. Here the use of descriptive bands to derive a combined rating is the defining marker of qualitative analysis.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
7/10 · Business Analysis Practices in Cybersecurity
While documenting requirements for a healthcare records system, a business analyst notes a requirement that medical data must be protected so that only authorized clinicians can view a patient's record. Which element of the CIA triad does this requirement primarily address?
AAvailability
BNon-repudiation
CIntegrity
DConfidentiality
Show answer & explanation
D is correct. The CIA triad — confidentiality, integrity, and availability — is a foundational security model. Confidentiality is about restricting access to authorized parties only, which is exactly what limiting record viewing to authorized clinicians accomplishes. Integrity addresses accuracy and unauthorized change, while availability addresses timely access. Non-repudiation, though important, is not part of the core triad.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
8/10 · Compliance and Governance
An online retailer that stores and processes payment card data is launching a new checkout service. Leadership asks the business analyst to identify which external standard most directly governs the protection of the cardholder data the new service will handle. Which obligation should the BA flag as the primary driver for the service's data-protection requirements?
AHIPAA, because it sets the baseline for protecting any sensitive consumer information.
BSOX, because it dictates the technical encryption standards for all customer-facing applications.
CPCI DSS, because it specifically governs the secure handling, storage, and transmission of payment cardholder data.
DISO/IEC 27001 certification, because it is legally required before processing any card payments.
Show answer & explanation
C is correct. The cybersecurity BA must map each regulatory or contractual obligation to the data and processes in scope. Cardholder data triggers PCI DSS, a contractually mandated standard for the payment ecosystem. HIPAA (health data), SOX (financial reporting), and ISO/IEC 27001 (voluntary ISMS) are real frameworks but do not directly govern payment card data protection.
↗ IIBA-CCA body of knowledge — Compliance and Governance
9/10 · Cybersecurity Risk Management · hard
Six months after a solution went live, the threat landscape has shifted: a new class of attack now targets the technology the solution uses, and a previously low-rated risk may no longer reflect reality. The BA wants to ensure the organization's risk picture stays accurate over time rather than being a one-time exercise. Which practice best addresses this need, and why is it important?
AReplacing the qualitative ratings with a single quantitative figure, because numbers make reassessment unnecessary
BLocking the risk register after go-live, because reopening assessed risks introduces unnecessary churn
CContinuous monitoring and periodic reassessment of risks, because risk levels change as threats, assets, and controls evolve
DTransferring all post-launch risks to an insurer, because operational risk is no longer the organization's concern after deployment
Show answer & explanation
C is correct. Cybersecurity risk management is iterative, not a one-time event. Because threats emerge, assets change, and control effectiveness degrades, organizations must continuously monitor risks and reassess them on a periodic and event-driven basis (for example, when a new attack class appears). This keeps risk ratings, ownership, and responses accurate so decisions remain grounded in current reality. The other options either freeze the picture, misuse transfer, or wrongly assume a metric removes the need to revisit risk.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
10/10 · Cybersecurity Foundations · hard
During a workshop, a business analyst helps the team evaluate two cyber risks. Risk X is very likely to occur but would cause only minor, easily recovered disruption. Risk Y is unlikely but, if it occurred, would cause a catastrophic, business-ending loss. Stakeholders want guidance on which risk should typically receive the higher priority for treatment. What is the most appropriate BA response based on qualitative risk analysis?
AAlways prioritize the risk with the higher impact regardless of its likelihood
BAlways prioritize the risk with the higher likelihood regardless of its impact
CPrioritize based on the combination of likelihood and impact, recognizing that a low-likelihood, catastrophic risk can outrank a high-likelihood, minor one
DTreat both risks identically because each has one high factor and one low factor
Show answer & explanation
C is correct. Qualitative risk analysis rates each risk by combining likelihood and impact, often on a risk matrix. Neither factor alone determines priority; their combination does. A catastrophic, business-ending impact can push even a low-likelihood risk into a high-priority band, so it may outrank a frequent but trivial risk. The BA should guide stakeholders to assess both dimensions together rather than relying on a single factor or assuming the factors cancel out.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
Practice by knowledge area
Five more free questions for each section of the IIBA-CCA bank, drawn from that area only, with the answer explained and linked to the source:
Covering every competency areas
The bank spans the whole IIBA-CCA blueprint, weighted toward what the exam tests most:
Start practising IIBA-CCA free
6 free questions · full study mode · per-area readiness · no card, no dumps, no ads.
Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026)
ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA.
PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data
PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
IIBA-CCA practice — FAQ
How many questions is the IIBA-CCA exam and how long is it?
75 multiple-choice knowledge-based questions in 90 minutes.
What is the passing score for IIBA-CCA?
IIBA does not publish a numeric cut score — results are pass/fail with per-area performance indicators. Aim for a consistent 80–85% on realistic mocks before booking.
What is the IIBA-CCA pass rate?
IIBA does not publish official pass rates, so any exact percentage quoted online is unverified. The readiness signal that actually predicts passing: consistently holding 80–85% on realistic, full-length practice exams before you book.
What are the IIBA-CCA eligibility requirements?
No formal prerequisites — no required work experience, PD hours, or references. IIBA recommends roughly 2 years of work in the specialty area.
How much does IIBA-CCA cost?
No application fee. Learning + Exam bundle $395 (member) / $550 (non-member); Learning-only $195 / $250 — check iiba.org for current packaging.
How long should I study for IIBA-CCA?
For most candidates, around 25–45 hours (no official IIBA figure). What matters most is practising questions and analysing why each option is right or wrong — not just reading.
Does the IIBA-CCA certification need recertification?
None — the CCA is a knowledge-based certificate and does not expire.
Are ExamDeck's IIBA-CCA questions exam dumps?
No — every question is original, written to test the concepts and reviewed before it ships, with an explanation linked to the source for every option. Dumps are stale, often wrong, and against IIBA's policies.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CCA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.