Practice CCOA Incident Detection And Response questions with full explanations on every answer.
Start practicing
Incident Detection And Response — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which TWO of the following actions are considered best practices during the 'Containment' phase of an incident response workflow?
2You are configuring a Splunk Enterprise Security (ES) Correlation Search to detect potential brute-force activity. You need to ensure the search generates a notable event only when the threshold of 10 failed logins occurs within a 5-minute window for a specific user. Which Correlation Search attribute should be modified?
3You are using an ELK Stack (Elasticsearch, Logstash, Kibana) for incident response. You have identified a time-based spike in traffic. What is the most efficient way to query for the top 10 unique source IP addresses for a specific destination over the last hour using Kibana Discover?
4You are investigating an EDR alert showing suspicious PowerShell execution. You need to identify the parent process that spawned the malicious script. Which tool or view would best allow you to visualize this process tree?
5You are managing an incident where an adversary is utilizing a 'Living off the Land' (LotL) technique. Which log source is most critical to detect this activity?
6During a Microsoft Sentinel incident investigation, you notice that a specific alert triggered by a custom analytic rule is creating too many false positives due to a noisy service account. You want to exclude this account without disabling the entire rule. What is the most effective approach?
7When performing digital forensics on a volatile memory dump, which THREE artifacts should you prioritize to identify evidence of fileless malware?
8When performing containment of a compromised endpoint in CrowdStrike Falcon, which feature should you use to prevent the adversary from using the machine to move laterally while still allowing incident responders to pull memory dumps?
9You are configuring a Splunk Enterprise Security notable event action. Which setting ensures the notable event remains in the 'In Progress' state until a specific analyst manually updates the status?
10You are investigating a suspected data exfiltration incident. You need to analyze network traffic captured in a PCAP file. Which tool is the industry standard for performing deep packet inspection and protocol analysis during this investigation?
11During a triage process, you need to identify the process tree of a suspicious PowerShell execution on a Windows host using Sysmon. Which Event ID should you filter for?
12While using Microsoft Sentinel, you observe that incidents are not triggering for brute force attempts despite a KQL rule being enabled. What is the most likely cause related to the 'Incident Settings' configuration?
13In the context of the NIST Incident Response lifecycle, which phase involves the root cause analysis and the documentation of lessons learned?
14You are investigating an alert in CrowdStrike Falcon. To determine if a file was moved laterally after its initial execution, which feature provides the most accurate visualization?
15When analyzing a memory dump using Volatility 3, which plugin is most effective for detecting code injection in a suspicious process?
16A user reports they cannot access a shared drive following a suspected ransomware infection. What is the immediate containment action according to standard incident response best practices?
17In a Palo Alto Networks environment, you need to identify if a specific internal host is beaconing to a command-and-control server. Which log type provides the necessary data?
18When using Wireshark to investigate a data exfiltration incident, you want to filter for TCP streams involving a specific internal IP that are larger than 1MB. How is this achieved?
19You are investigating a suspicious login in Okta. Which log field should be analyzed to determine if the session originated from an anonymized VPN or Tor exit node?
20You are performing a digital forensic image of a SATA drive. Which tool is standard for creating a bit-stream image while ensuring data integrity via a hash verification?
21A security analyst is triaging an alert about an unauthorized login from an unusual country. What is the first priority in the response workflow?
22You are reviewing AWS CloudTrail logs to investigate an unauthorized modification of an S3 bucket policy. Which event name should you search for?
23During an investigation, you discover a malicious cron job on a Linux server. Which directory is the primary location for user-specific cron tasks?
24You are auditing a Linux server for persistence mechanisms. Which file is commonly used by attackers to hide malicious code that executes upon every user login?
25A SIEM has triggered an alert for 'Excessive Failed Login Attempts' followed by a 'Successful Login'. Which technique is this most likely attempting to detect?
26In the context of the NIST Incident Response lifecycle, which phase involves the identification of the root cause?
27A security appliance flags a high volume of traffic from a single internal host to a series of random external IP addresses. This is a classic indicator of which activity?
28After an incident, you need to preserve the volatile memory of a compromised machine. What is the correct order of operations according to the Order of Volatility?
29While investigating an incident in Google Workspace, you notice suspicious file sharing. Which log type should be queried to see which files were shared externally by a specific user?
30You are investigating a PowerShell-based attack. The attacker is using Base64 encoded commands. Which command line switch often indicates the use of encoded code?
31You are configuring a 'Watchlist' in Sentinel to detect when a specific list of known malicious IPs interact with your environment. What is the correct method to map this watchlist to an analytics rule?
32Which type of log provides the most granular detail regarding local account creation on a Windows Server?
33You are investigating a suspicious process on Windows. You see it is running from 'C:\ProgramData'. Which tool allows you to check if the process signature is valid?
34A SIEM alert indicates a 'Golden Ticket' attack. What is the primary indicator of this attack in the logs?
35When drafting an incident report, what is the most important element to include for the executive summary?
36You are analyzing a PCAP file and see numerous 'ICMP Echo Request' packets with unusually large payloads. What is this likely indicative of?
37In an Azure environment, you detect a malicious actor performing 'Pass-the-Token' attacks. Which sign-in log detail confirms this?
38You are analyzing an endpoint and suspect a fileless malware attack. Which of the following is the most likely location for the malicious script to reside?
39While investigating a web server breach, you find malicious PHP web shells. What is the most effective way to identify the source of the upload?
40A phishing simulation resulted in a user clicking a link. What is the next logical step in the incident response process?
41What is a 'False Positive' in the context of SIEM alerting?
42You are investigating a potential credential harvesting site. Which tool is best suited to safely inspect the site without triggering a potential infection?
43Which type of evidence is collected to prove that a specific individual was responsible for an action on a system?
44In a Linux system, which tool is used to identify open network connections and the specific process ID (PID) associated with them?
45What is the primary goal of the 'Eradication' phase in incident response?
46During a forensic analysis, you find a suspicious file that was renamed to look like a system file. What is the most reliable way to identify its true nature?
47You are investigating a potential insider threat. Which log is most useful for tracking file deletion activity on a Windows file server?
48You are monitoring a network and detect a large number of ARP requests from a single host targeting the entire subnet. This is a sign of what?
49You are analyzing an incident where a user's machine was compromised via a malicious document. Which Windows log indicates that a macro was executed?
50Which TWO actions are required to properly secure a compromised user account during the eradication phase?
51When a workstation is compromised, why is it recommended to isolate it rather than turning it off?
52Which THREE of the following are common sources for SIEM data ingestion to assist in incident detection?
53Which TWO tools are commonly used for memory forensic analysis?
54Which THREE indicators should an analyst monitor to identify a potential web server compromise?
55Which TWO of the following are essential components of an effective Incident Response Plan (IRP)?
56Which THREE types of data are typically found in a full forensic disk image?
57Which TWO documents are essential to provide to a forensic investigator?
58Which THREE behaviors are characteristic of a potential data exfiltration attempt?
59Which THREE phases of the incident response lifecycle involve the most interaction with stakeholders?
60Which TWO of the following are true regarding the use of hashing in digital forensics?
61Which THREE types of network logs are most effective for identifying a data breach?
62Which TWO of the following Windows log types are most useful for detecting lateral movement?
63Which THREE techniques do attackers use to maintain persistence on a Windows host?
64Which TWO actions should be taken if an incident is confirmed to involve sensitive PII?
65Which THREE factors should be considered when assessing the severity of a security incident?
66Which THREE steps are part of the 'Preparation' phase of incident response?
67Which TWO sources are used to populate threat intelligence feeds for incident detection?
68A security analyst is configuring an alert in Splunk Enterprise Security to detect potential brute force attacks. The analyst must identify the specific notable event aggregate field that prevents the creation of duplicate alerts for the same source IP over a defined time window. Which field should be utilized?
69During a digital forensics investigation of a Windows host, an analyst suspects an attacker used PowerShell 'Fileless' execution. Which artifact within the Windows Event Logs would provide the most definitive evidence of the specific command line arguments used during the execution?
70An incident response team is performing containment on a compromised Linux server that is part of a containerized environment. Given that the container is running in a Kubernetes cluster, which action is the most appropriate initial containment step to preserve the volatile memory for forensics while preventing further data exfiltration?
71When classifying a security incident using the NIST SP 800-61 framework, which phase is focused on identifying the precursors and indicators of an attack?
72A security analyst is investigating a suspected beaconing behavior in network traffic logs. The traffic consistently shows small, periodic connections to an external IP. Which statistical analysis method is most effective for identifying this pattern within high-volume PCAP or NetFlow data?
73During an incident response engagement involving a ransomware attack, the team decides to isolate the affected endpoint using an EDR solution. What is the expected behavior of the EDR tool during the 'network isolation' process?
74A CISO asks for a list of indicators that should be monitored in the SIEM to detect potential account takeover attempts. Which THREE indicators are most relevant?
75Which of the following activities is best categorized as an 'eradication' step in the incident response lifecycle?
76When conducting digital forensics on a volatile memory dump using the Volatility Framework, which TWO plugins would be most effective in identifying malicious kernel-mode rootkits?
77During the post-incident recovery phase, which TWO actions are essential to ensure the environment is returned to a secure state?
The Incident Detection And Response domain covers the key concepts tested in this area of the CCOA exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CCOA domains — no account required.
The Courseiva CCOA question bank contains 77 questions in the Incident Detection And Response domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Detection And Response domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included