Practice CCOA Adversarial Tactics questions with full explanations on every answer.
Start practicing
Adversarial Tactics — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are auditing an environment for 'T1083 File and Directory Discovery'. Which log source provides the most visibility into this activity?
2While analyzing an EDR alert, you observe a process modifying 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. What is the primary adversary objective at this stage?
3In the context of the MITRE ATT&CK framework, what distinguishes 'T1059 Command and Scripting Interpreter' from 'T1204 User Execution'?
4You are configuring a YARA rule for CrowdStrike Falcon to detect Cobalt Strike Beacon traffic. Which specific technique should you look for in the process memory that indicates process hollowing?
5You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?
6An adversary uses 'vssadmin.exe delete shadows /all /quiet' during an attack. Which tactic is this technique categorized under?
7You are configuring Microsoft Defender for Endpoint. Which feature is most effective against 'T1566 Phishing'?
8Which action constitutes 'Discovery' as defined by the MITRE ATT&CK framework?
9What is the purpose of 'T1027 Obfuscated Files or Information'?
10Which of the following is considered an 'Execution' tactic in the MITRE ATT&CK framework?
11You are reviewing a Purple Team exercise involving 'T1003 OS Credential Dumping'. What is the most reliable way to detect credential dumping via LSASS process access?
12What is the primary difference between a Red Team and a Blue Team in a security simulation?
13You see a process performing DNS queries for unusually long subdomains. Which tactic is the adversary likely exercising?
14You detect an adversary attempting to clear Windows Event Logs using 'wevtutil cl'. This falls under which tactic?
15Which technique is most effective for an adversary to perform 'T1078 Valid Accounts'?
16What is the primary goal of the 'Command and Control' (C2) tactic?
17Which of these is a typical 'Lateral Movement' technique?
18You are implementing threat hunting for 'T1562 Impair Defenses'. Which activity are you searching for?
19What is the primary function of a 'C2 Beacon'?
20An adversary is using a living-off-the-land (LotL) binary to execute commands. Why is this preferred over a custom malware?
21Which of these is a 'Defense Evasion' technique?
22You are investigating a breach where the attacker used 'T1555 Credentials from Password Stores'. Where would they look?
23You suspect an adversary is performing 'T1005 Data from Local System'. Which of these actions is relevant?
24An attacker uses 'T1133 External Remote Services' to gain access. What does this involve?
25Which tactic is associated with 'T1537 Transfer Data to Cloud Account'?
26During a simulation, you notice a process spawning child processes from 'wmic.exe'. What is this technique often used for?
27Which TWO of the following are examples of 'Initial Access' tactics?
28You are assessing an attacker's use of 'T1203 Exploitation for Client Execution'. What does this imply?
29Which TWO of the following are examples of 'Persistence' tactics?
30Which TWO of the following behaviors are typical of 'Lateral Movement'?
31Which TWO of the following are considered 'Credential Access' techniques?
32Which TWO of the following are examples of 'Discovery' techniques?
33Which TWO of the following are considered 'Defense Evasion' techniques?
34Which THREE of the following are common 'Exfiltration' techniques?
35Which THREE of the following are considered 'Execution' techniques?
36Which THREE of the following are common 'Impact' techniques?
37Which THREE of the following are 'Command and Control' techniques?
38Which THREE of the following are 'Privilege Escalation' techniques?
39Which THREE of the following are considered 'Collection' techniques?
The Adversarial Tactics domain covers the key concepts tested in this area of the CCOA exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CCOA domains — no account required.
The Courseiva CCOA question bank contains 39 questions in the Adversarial Tactics domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Adversarial Tactics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included