HomeBusiness AnalysisIIBA-CCAPractice questionsBusiness Analysis Practices in Cybersecurity
IIBA-CCA · IIBA · Business Analysis Practices in Cybersecurity · Bank updated 2026-07-02

IIBA-CCA practice questions: Business Analysis Practices in Cybersecurity

5 free questions from 76 on this area · answer and explanation for each · no sign-up

These 5 questions come from the Business Analysis Practices in Cybersecurity section of our IIBA-CCA bank (76 questions on this area). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All IIBA-CCA sample questions
1/5 · Business Analysis Practices in Cybersecurity
A business analyst is helping prioritize remediation across a portfolio of identified threats. The security lead asks the BA to estimate the level of risk each threat poses so that limited resources can be directed appropriately. Which combination of factors should the BA use to determine the level of risk for each threat?
AThe number of vulnerabilities reported in the last vulnerability scan
BThe cost of the control multiplied by the number of affected users
CThe likelihood of the threat occurring combined with the impact if it materializes
DThe maturity of the organization's security awareness training program
Show answer & explanation
C is correct. Cybersecurity risk analysis assesses risk as a function of likelihood and impact. By estimating how probable a threat is and how severe its consequences would be, the BA can help rank threats and direct remediation resources to the highest-risk items. Cost, vulnerability counts, and training maturity are inputs or mitigating factors, not the definition of risk level.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
2/5 · Business Analysis Practices in Cybersecurity
While eliciting access requirements for a new HR system, a manager requests that all members of her team be granted broad administrative rights 'to avoid bottlenecks.' The business analyst recognizes a tension with sound security practice and recommends instead that each role be granted only the access strictly necessary to perform its job functions. Which security principle is the BA invoking to shape the access requirements?
AThe principle of non-repudiation, ensuring actions cannot later be denied by the actor
BThe principle of fail-safe defaults applied to network firewall rules
CThe principle of defense in depth, layering multiple independent controls
DThe principle of least privilege, granting each role only the minimum access necessary to perform its functions
Show answer & explanation
D is correct. Granting each role only the access strictly necessary to do its job is the definition of least privilege, a core access-control principle the BA uses to push back on excessive administrative rights. Non-repudiation, fail-safe defaults, and defense in depth are distinct security concepts that do not describe minimizing each role's access scope.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
3/5 · Business Analysis Practices in Cybersecurity
While eliciting requirements for a marketing analytics feature, a stakeholder requests that the application collect each visitor's full date of birth, home address, and government ID number, although the analytics use case only needs an approximate age range. A privacy-aware business analyst challenges the request. Which privacy principle most directly supports the analyst's challenge?
ANon-repudiation — ensuring a party cannot deny having performed an action.
BSeparation of duties — dividing critical tasks among different people to prevent fraud.
CData minimization — collecting only the personal data that is adequate, relevant, and necessary for the specified purpose.
DDefense in depth — layering multiple controls so failure of one does not compromise the system.
Show answer & explanation
C is correct. Data minimization is a core privacy principle requiring that only personal data necessary and relevant to the stated purpose be collected. When a use case needs only an approximate age range, requesting full date of birth, address, and government ID violates this principle. The analyst applies data minimization to push back and shape requirements that reduce privacy risk and regulatory exposure.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
4/5 · Business Analysis Practices in Cybersecurity
A board wants to know whether the organization's security maturity is ahead of, in line with, or behind comparable firms in its sector before approving further investment. The business analyst is asked to produce an external comparison that positions the organization's practices relative to peers and recognized industry norms. Which technique best meets this request?
AA misuse case modeling an attacker abusing the login feature
BBenchmarking against peer organizations and recognized industry maturity baselines
CA data flow diagram of the organization's payment systems
DA traceability matrix linking controls to regulatory obligations
Show answer & explanation
B is correct. Benchmarking and market analysis compare an organization's performance or maturity against peers and recognized external baselines, giving leadership an outside-in view to judge whether to invest further. That is exactly what the board asked for. Data flow diagrams, misuse cases, and traceability matrices are valuable internal analysis and modeling tools, but none provide the external, peer-relative positioning that benchmarking delivers. Supplying this comparative context is a recognized BA contribution when justifying security strategy.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
5/5 · Business Analysis Practices in Cybersecurity · easy
Before onboarding a new cloud-based payroll vendor that will store employee bank account details, a business analyst is asked to gather evidence of the vendor's security certifications, data handling practices, and history of past breaches. This activity is an example of which practice?
ABusiness process reengineering, redesigning the payroll process for efficiency
BA third-party (vendor) security risk assessment
CAcceptance testing, verifying that delivered software meets agreed criteria
DChange impact analysis, assessing the effects of a proposed change on existing systems
Show answer & explanation
B is correct. A third-party security risk assessment evaluates whether an external vendor's security controls, certifications, and track record are adequate before that vendor is granted access to sensitive organizational data. Business analysts often coordinate this due diligence as part of the requirements for vendor selection and contracting.
↗ IIBA-CCA body of knowledge — Business Analysis Practices in Cybersecurity
Practise all 76 Business Analysis Practices in Cybersecurity questions - start free → See the whole IIBA-CCA bank

Other IIBA-CCA areas

The same kind of free sample for every other section of the IIBA-CCA bank:

Cybersecurity Foundations77 qCybersecurity Risk Management75 qCompliance and Governance75 q

Study Business Analysis Practices in Cybersecurity with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026) ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA. PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CCA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.