Courseiva

CCOA · domain

Adversarial Tactics

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Adversarial Tactics practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

39 questions14 easy12 medium13 hard

Focused practice

Practice Adversarial Tactics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Adversarial Tactics

Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Adversarial Tactics exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Adversarial Tactics questions (39)

Click any question to see the full explanation, or start a practice session above.

1

Which tactic is associated with 'T1537 Transfer Data to Cloud Account'?

Easy
2

What is the primary goal of the 'Command and Control' (C2) tactic?

Medium
3

You suspect an adversary is performing 'T1005 Data from Local System'. Which of these actions is relevant?

Medium
4

You are assessing an attacker's use of 'T1203 Exploitation for Client Execution'. What does this imply?

Hard
5

Which TWO of the following are examples of 'Discovery' techniques?

Medium
6

You are investigating a breach where the attacker used 'T1555 Credentials from Password Stores'. Where would they look?

Hard
7

You are implementing threat hunting for 'T1562 Impair Defenses'. Which activity are you searching for?

Hard
8

Which TWO of the following are considered 'Defense Evasion' techniques?

Hard
9

You are reviewing a Purple Team exercise involving 'T1003 OS Credential Dumping'. What is the most reliable way to detect credential dumping via LSASS process access?

Hard
10

You see a process performing DNS queries for unusually long subdomains. Which tactic is the adversary likely exercising?

Medium
11

Which technique is most effective for an adversary to perform 'T1078 Valid Accounts'?

Hard
12

While analyzing an EDR alert, you observe a process modifying 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. What is the primary adversary objective at this stage?

Medium
13

What is the purpose of 'T1027 Obfuscated Files or Information'?

Easy
14

Which TWO of the following are considered 'Credential Access' techniques?

Easy
15

Which of these is a typical 'Lateral Movement' technique?

Easy
16

In the context of the MITRE ATT&CK framework, what distinguishes 'T1059 Command and Scripting Interpreter' from 'T1204 User Execution'?

Hard
17

Which THREE of the following are common 'Impact' techniques?

Hard
18

An adversary uses 'vssadmin.exe delete shadows /all /quiet' during an attack. Which tactic is this technique categorized under?

Easy
19

What is the primary function of a 'C2 Beacon'?

Easy
20

Which TWO of the following behaviors are typical of 'Lateral Movement'?

Hard
21

You are configuring Microsoft Defender for Endpoint. Which feature is most effective against 'T1566 Phishing'?

Easy
22

You are auditing an environment for 'T1083 File and Directory Discovery'. Which log source provides the most visibility into this activity?

Medium
23

You are configuring a YARA rule for CrowdStrike Falcon to detect Cobalt Strike Beacon traffic. Which specific technique should you look for in the process memory that indicates process hollowing?

Hard
24

You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?

Easy
25

Which THREE of the following are 'Command and Control' techniques?

Medium
26

An adversary is using a living-off-the-land (LotL) binary to execute commands. Why is this preferred over a custom malware?

Medium
27

What is the primary difference between a Red Team and a Blue Team in a security simulation?

Hard
28

Which THREE of the following are considered 'Collection' techniques?

Easy
29

During a simulation, you notice a process spawning child processes from 'wmic.exe'. What is this technique often used for?

Medium
30

Which of the following is considered an 'Execution' tactic in the MITRE ATT&CK framework?

Easy
31

Which action constitutes 'Discovery' as defined by the MITRE ATT&CK framework?

Easy
32

Which TWO of the following are examples of 'Initial Access' tactics?

Easy
33

An attacker uses 'T1133 External Remote Services' to gain access. What does this involve?

Hard
34

Which of these is a 'Defense Evasion' technique?

Easy
35

Which THREE of the following are considered 'Execution' techniques?

Medium
36

Which THREE of the following are 'Privilege Escalation' techniques?

Hard
37

Which THREE of the following are common 'Exfiltration' techniques?

Easy
38

Which TWO of the following are examples of 'Persistence' tactics?

Medium
39

You detect an adversary attempting to clear Windows Event Logs using 'wevtutil cl'. This falls under which tactic?

Medium

Frequently asked questions

What does the Adversarial Tactics domain cover on the CCOA exam?
Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 39 Adversarial Tactics questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Adversarial Tactics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-ccoa ISACA-CCOA adversarial tactics Practice Questions