10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free CCBTO questions are organized by exam domain, so you can see how each part of the Certified Community Bank Technology Officer blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Understand IT budgeting and systems selection.
Question 1
A core-system conversion rehearsal produces the same deposit-account count and total dollar balance as the legacy system. The conversion also replaces customer identifiers, but the identifier mappings have not been validated. Before approving the financial-data conversion, the technology officer needs evidence from which additional test?
Show answer & explanation
Correct answer: B - Validate customer-account mappings and reconcile individual balances across the two systems.
Question 2
An automation project meets every mandatory security and operational requirement. It costs $180,000 initially and $48,000 annually. Each year it eliminates a $96,000 outside-processing contract and $24,000 of overtime. It also frees staff time valued at $60,000, but those employees will be reassigned with no payroll reduction. Annual savings and costs remain constant and accrue evenly; ignore tax and discounting. Funding requires a simple cash payback within three years. Which recommendation is supported?
Show answer & explanation
Correct answer: C - Fund it: 2.5 years, using the annual cash savings after the new operating expense.
Question 3
A bank is negotiating a loan-document SaaS contract. It owns its data, but the proposed agreement offers only individual document downloads. The service stores document versions, signatures, and links to loan records in a proprietary structure. To make a future transition to another provider feasible, which contractual addition addresses the principal gap?
Show answer & explanation
Correct answer: A - Bulk export of documents and metadata in usable formats, with defined timing and assistance.
Domain 2: Learn cloud trends.
Question 4
Developers deploy a bank's application to a platform-as-a-service offering. The provider maintains the operating system and runtime; the bank packages and deploys its own application code and third-party libraries. A critical flaw is found in one of those packaged libraries, while the managed runtime is fully patched. There is no separate application-management agreement. Who must correct the vulnerable component?
Show answer & explanation
Correct answer: A - The bank, by updating and testing the deployed application library.
Question 5
Online banking runs across two availability zones in one cloud region. An exercise takes one zone offline, and customers continue transacting through the other. All application replicas, databases, and backups remain in that same region. The board's separate regional-disaster objective has not been tested. The exercise supports which conclusion?
Show answer & explanation
Correct answer: C - The tested zone failure was tolerated; recovery from loss of the whole region remains unproven.
Domain 3: Be familiar with asset management.
Question 6
An independently reconciled inventory identifies 480 active workstations that require endpoint protection. The security console lists 400 of them: 380 have functioning protection and 20 have failed agents. The remaining 80 do not report to the console. A dashboard presents 95% protection coverage. Which replacement accurately reports verified protection across the entire in-scope workstation population?
Show answer & explanation
Correct answer: C - About 79%: compare functioning protection with all 480 in-scope workstations.
Question 7
A failed solid-state drive contains unencrypted customer records. It no longer accepts read, write, or sanitization commands, and the bank has authorized its disposal. Which proposed disposition supports effective sanitization before release?
Show answer & explanation
Correct answer: D - Arrange validated physical destruction of the flash-memory components and retain a record of the disposition.
Domain 4: Gain knowledge of cybersecurity tactics.
Question 8
Minutes before wire cutoff, a commercial customer's usual email account sends new beneficiary instructions in an existing payment thread. The message includes a phone number for verification. A bank employee calls that number and receives verbal confirmation, but the wire has not been released. No independent verification has occurred. What should the bank do with the pending wire?
Show answer & explanation
Correct answer: D - Hold this wire and verify the change using the customer's previously established contact number.
Question 9
A vulnerability-triage worksheet lists three values: CVSS v4.0 Base score, 8.6; EPSS exploitation probability, 18%; EPSS percentile, 96. The technology officer needs an accurate description of what these measures establish. The defensible reading is:
Show answer & explanation
Correct answer: A - High technical severity; EPSS estimates an 18% chance of exploitation in the wild over the next 30 days.
Question 10
A ransomware exercise reveals that a compromised production administrator can delete every online backup and the disaster-recovery replicas. Restoring from those copies is fast enough when they exist, and backup jobs complete successfully. Only one improvement can be funded immediately. Which proposal corrects the failure the exercise exposed?
Show answer & explanation
Correct answer: B - Add retention-locked backup copies that production administrators cannot delete or unlock.
That's 10 of 1,030
The full bank has 1,020 more CCBTO questions with explanations.