Sample questions
ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) practice questions
Which of these is a typical 'Lateral Movement' technique?
Which THREE of the following are 'Command and Control' techniques?
You are auditing an environment for 'T1083 File and Directory Discovery'. Which log source provides the most visibility into this activity?
Which action constitutes 'Discovery' as defined by the MITRE ATT&CK framework?
Which TWO of the following are examples of 'Persistence' tactics?
While analyzing an EDR alert, you observe a process modifying 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. What is the primary adversary objective at this stage?
Which THREE of the following are 'Privilege Escalation' techniques?
Which TWO of the following are examples of 'Detection' capabilities in the NIST CSF?
Which role is primarily responsible for classifying data based on its value and sensitivity to the organization?
You are investigating a suspicious login in Okta. Which log field should be analyzed to determine if the session originated from an anonymized VPN or Tor exit node?
You are configuring a 'Watchlist' in Sentinel to detect when a specific list of known malicious IPs interact with your environment. What is the correct method to map this watchlist…
During a digital forensics investigation of a Windows host, an analyst suspects an attacker used PowerShell 'Fileless' execution. Which artifact within the Windows Event Logs would…
Which THREE of the following are considered 'Execution' techniques?
You are tasked with ensuring the 'Confidentiality' of sensitive data in transit. Which mechanism best satisfies this security principle?
You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?
You see a process performing DNS queries for unusually long subdomains. Which tactic is the adversary likely exercising?
In the context of the MITRE ATT&CK framework, what distinguishes 'T1059 Command and Scripting Interpreter' from 'T1204 User Execution'?
You are implementing threat hunting for 'T1562 Impair Defenses'. Which activity are you searching for?
You are assessing an attacker's use of 'T1203 Exploitation for Client Execution'. What does this imply?
You are investigating an EDR alert showing suspicious PowerShell execution. You need to identify the parent process that spawned the malicious script. Which tool or view would best…
A user reports they cannot access a shared drive following a suspected ransomware infection. What is the immediate containment action according to standard incident response best p…
During a simulation, you notice a process spawning child processes from 'wmic.exe'. What is this technique often used for?
Which THREE of the following are common 'Impact' techniques?
A security analyst is mapping organizational assets to the NIST Cybersecurity Framework. Which category is specifically responsible for maintaining the resilience of critical infra…