HomeBusiness AnalysisIIBA-CCAPractice questionsCybersecurity Foundations
IIBA-CCA · IIBA · Cybersecurity Foundations · Bank updated 2026-07-02

IIBA-CCA practice questions: Cybersecurity Foundations

5 free questions from 77 on this area · answer and explanation for each · no sign-up

These 5 questions come from the Cybersecurity Foundations section of our IIBA-CCA bank (77 questions on this area). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All IIBA-CCA sample questions
1/5 · Cybersecurity Foundations
An organization deploys an intrusion detection system that generates alerts when anomalous network traffic patterns occur, but it does not block the traffic itself. When a business analyst categorizes this control for the security requirements specification, which control type best describes it?
ACorrective control
BCompensating control
CPreventive control
DDetective control
Show answer & explanation
D is correct. Security controls are commonly classified by function: preventive controls stop incidents, detective controls identify them, and corrective controls remediate or restore after them. An intrusion detection system that only raises alerts is detective because it identifies suspicious activity without preventing it. (An intrusion prevention system that actively blocks would be preventive.) Accurate classification helps the BA ensure the control set provides defense in depth.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
2/5 · Cybersecurity Foundations · hard
After a risk assessment, the organization decides to purchase cyber insurance to cover potential losses from a low-likelihood but high-impact ransomware event, while continuing operations as usual. In risk treatment terms, which option has the organization primarily chosen?
ARisk mitigation
BRisk avoidance
CRisk transfer
DRisk acceptance
Show answer & explanation
C is correct. Risk treatment options include avoid, mitigate/reduce, transfer/share, and accept. Buying insurance to cover financial loss is risk transfer because the financial consequence is moved to another party, even though the underlying likelihood remains unchanged.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
3/5 · Cybersecurity Foundations · hard
A BA captures the statement 'All session tokens must be invalidated within 30 seconds of a user logging out.' The team debates where this belongs in the requirements documentation. How should the BA most accurately characterize and place this statement?
AAs a non-functional (security) requirement, because it specifies a quality constraint on system behavior
BAs an assumption, because it presumes tokens exist in the design
CAs a business rule, because it reflects organizational policy independent of any system
DAs a functional requirement, because logout is a feature users perform
Show answer & explanation
A is correct. Security requirements typically manifest as non-functional requirements—measurable constraints on qualities such as how securely, how quickly, or how reliably a system behaves. A bounded token-invalidation time is a security quality constraint, so it is documented as a non-functional (security) requirement.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
4/5 · Cybersecurity Foundations
In a security briefing, three terms are used: an unpatched flaw in the login service, a criminal group known to target such services, and the specific malicious code that takes advantage of the flaw. Which mapping of these descriptions to security terminology is correct?
AThe unpatched flaw is the exploit, the criminal group is the vulnerability, the malicious code is the threat
BThe unpatched flaw is the threat, the criminal group is the vulnerability, the malicious code is the exploit
CAll three terms are interchangeable ways of describing the same risk event
DThe unpatched flaw is the vulnerability, the criminal group is the threat (actor), the malicious code is the exploit
Show answer & explanation
D is correct. Precise vocabulary underpins risk analysis. A vulnerability is a weakness that could be leveraged (the unpatched login flaw). A threat is a potential cause of harm, often embodied by a threat actor (the criminal group). An exploit is the specific method or code that takes advantage of a vulnerability (the malicious code). Risk arises when a threat actor can use an exploit against a vulnerability affecting a valued asset. The analyst who keeps these terms distinct can document and communicate security issues without ambiguity.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
5/5 · Cybersecurity Foundations
A business analyst is gathering requirements for onboarding a new cloud-based payroll vendor and includes questions about the vendor's data encryption practices, breach-notification obligations, and use of subcontractors within the requirements documentation. This activity primarily supports which security-related process?
AThird-party vendor risk assessment
BConfiguration management
CBusiness process reengineering
DChange impact analysis
Show answer & explanation
A is correct. Because outsourcing introduces risk that an organization does not directly control, third-party or vendor risk assessment gathers evidence about a vendor's security controls, compliance obligations, and subcontracting practices before a relationship is established. Business analysts often lead the elicitation of these questions as part of vendor onboarding requirements.
↗ IIBA-CCA body of knowledge — Cybersecurity Foundations
Practise all 77 Cybersecurity Foundations questions - start free → See the whole IIBA-CCA bank

Other IIBA-CCA areas

The same kind of free sample for every other section of the IIBA-CCA bank:

Cybersecurity Risk Management75 qBusiness Analysis Practices in Cybersecurity76 qCompliance and Governance75 q

Study Cybersecurity Foundations with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026) ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA. PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CCA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.