IIBA-CCA · IIBA · Cybersecurity Risk Management · Bank updated 2026-07-02
IIBA-CCA practice questions: Cybersecurity Risk Management
5 free questions from 75 on this area · answer and explanation for each · no sign-up
These 5 questions come from the Cybersecurity Risk Management section of our IIBA-CCA bank (75 questions on this area). Every question is original, with the correct answer explained and linked to the source it is drawn from.
1/5 · Cybersecurity Risk Management
After analysis, an organization decides that the residual risk associated with a low-traffic legacy reporting feature is small enough that no further controls will be implemented; management formally acknowledges the exposure and authorizes continued operation as-is. Which risk response strategy has the organization chosen?
ARisk avoidance
BRisk acceptance
CRisk mitigation
DRisk transfer
Show answer & explanation
B is correct. The four common risk response strategies are avoid (eliminate the activity or exposure), transfer (shift consequence to another party), mitigate (reduce likelihood or impact with controls), and accept (knowingly tolerate the residual risk). When management consciously decides not to act on a risk whose residual level is within tolerance and documents that decision, the response is acceptance. Acceptance should always be a deliberate, authorized decision rather than an oversight.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
2/5 · Cybersecurity Risk Management
Having selected mitigation as the response to a high-priority risk, the team needs a document that specifies exactly which actions will be taken to reduce the risk, who is responsible for each, the target completion dates, and how progress will be tracked. Which artifact is the business analyst being asked to produce?
AA risk treatment plan
BA business impact analysis
CA vulnerability scan report
DA risk appetite statement
Show answer & explanation
A is correct. Once a response strategy is chosen, the risk treatment plan operationalizes it by detailing the specific actions, the responsible parties, target dates, required resources, and the means of tracking progress to completion. It bridges the decision (mitigate, transfer, etc.) and execution. A risk appetite statement sets strategic willingness, a business impact analysis evaluates disruption consequences, and a vulnerability scan report identifies weaknesses, so none of those is the implementation plan the scenario requires.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
3/5 · Cybersecurity Risk Management
An organization is onboarding a SaaS analytics vendor that will process customer personal data. The business analyst is reviewing the vendor's security posture as part of due diligence. Beyond the vendor's own controls, which additional risk dimension should the BA explicitly raise to give the assessment appropriate breadth?
AThe color scheme and usability of the vendor's administrative dashboard
BThe vendor's marketing spend relative to its competitors
CThe vendor's reliance on its own subcontractors and fourth parties that may also touch the data
DThe number of employees the vendor has at its headquarters
Show answer & explanation
C is correct. Third-party risk assessment must consider the vendor's own downstream dependencies, because subcontractors and fourth parties can introduce data exposure the primary vendor does not directly control. Raising this dimension broadens the due-diligence appropriately.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
4/5 · Cybersecurity Risk Management
A risk assessment finds that several employees retain broad system access acquired across previous roles, and the largest plausible exposure is a trusted user misusing or accidentally leaking sensitive data they no longer need. The business analyst is asked to recommend a treatment that reduces this exposure without removing legitimate access. Which requirement best addresses it?
ARequire a stronger perimeter firewall to block external attackers from reaching the data
BRequire all employees to sign an acceptable-use policy and consider the insider risk closed
CRequire the sensitive data to be encrypted in transit so it cannot be intercepted on the network
DRequire access to be granted on a least-privilege basis with periodic recertification, so each user holds only the permissions their current role requires
Show answer & explanation
D is correct. Insider risk from accumulated, unneeded access is best treated by least privilege with periodic recertification, which removes permissions the current role does not require while leaving legitimate access intact. Perimeter firewalls and transit encryption address external and interception threats, and a signed policy alone does not reduce the underlying excess access.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
5/5 · Cybersecurity Risk Management · hard
While modeling the accounts-payable process, a business analyst notices that the same employee role can both create a new vendor record and approve payments to that vendor, with no independent review step. This gap creates an elevated risk of fraudulent payments. What should the business analyst recommend?
AAdd multi-factor authentication to the accounts-payable application login
BSchedule more frequent employee security-awareness training
CIntroduce segregation of duties, such as requiring a second, independent role to approve new vendor records before payments can be issued
DIncrease the encryption strength used to store vendor payment data
Show answer & explanation
C is correct. The scenario describes a segregation-of-duties gap, a classic insider-threat and fraud risk where the same role controls two conflicting steps of a process without independent oversight. The appropriate remediation is a process control—separating those duties—rather than technical controls like encryption or MFA, or awareness training, which do not address the underlying process design flaw.
↗ IIBA-CCA body of knowledge — Cybersecurity Risk Management
Other IIBA-CCA areas
The same kind of free sample for every other section of the IIBA-CCA bank:
Study Cybersecurity Risk Management with instant feedback
6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.
Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026)
ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA.
PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data
PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CCA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.