CCOA · domain
Adversarial Tactics
Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Adversarial Tactics practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Adversarial Tactics questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Adversarial Tactics
Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Adversarial Tactics exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Adversarial Tactics questions (39)
Click any question to see the full explanation, or start a practice session above.
Which tactic is associated with 'T1537 Transfer Data to Cloud Account'?
Easy2What is the primary goal of the 'Command and Control' (C2) tactic?
Medium3You suspect an adversary is performing 'T1005 Data from Local System'. Which of these actions is relevant?
Medium4You are assessing an attacker's use of 'T1203 Exploitation for Client Execution'. What does this imply?
Hard5Which TWO of the following are examples of 'Discovery' techniques?
Medium6You are investigating a breach where the attacker used 'T1555 Credentials from Password Stores'. Where would they look?
Hard7You are implementing threat hunting for 'T1562 Impair Defenses'. Which activity are you searching for?
Hard8Which TWO of the following are considered 'Defense Evasion' techniques?
Hard9You are reviewing a Purple Team exercise involving 'T1003 OS Credential Dumping'. What is the most reliable way to detect credential dumping via LSASS process access?
Hard10You see a process performing DNS queries for unusually long subdomains. Which tactic is the adversary likely exercising?
Medium11Which technique is most effective for an adversary to perform 'T1078 Valid Accounts'?
Hard12While analyzing an EDR alert, you observe a process modifying 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. What is the primary adversary objective at this stage?
Medium13What is the purpose of 'T1027 Obfuscated Files or Information'?
Easy14Which TWO of the following are considered 'Credential Access' techniques?
Easy15Which of these is a typical 'Lateral Movement' technique?
Easy16In the context of the MITRE ATT&CK framework, what distinguishes 'T1059 Command and Scripting Interpreter' from 'T1204 User Execution'?
Hard17Which THREE of the following are common 'Impact' techniques?
Hard18An adversary uses 'vssadmin.exe delete shadows /all /quiet' during an attack. Which tactic is this technique categorized under?
Easy19What is the primary function of a 'C2 Beacon'?
Easy20Which TWO of the following behaviors are typical of 'Lateral Movement'?
Hard21You are configuring Microsoft Defender for Endpoint. Which feature is most effective against 'T1566 Phishing'?
Easy22You are auditing an environment for 'T1083 File and Directory Discovery'. Which log source provides the most visibility into this activity?
Medium23You are configuring a YARA rule for CrowdStrike Falcon to detect Cobalt Strike Beacon traffic. Which specific technique should you look for in the process memory that indicates process hollowing?
Hard24You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?
Easy25Which THREE of the following are 'Command and Control' techniques?
Medium26An adversary is using a living-off-the-land (LotL) binary to execute commands. Why is this preferred over a custom malware?
Medium27What is the primary difference between a Red Team and a Blue Team in a security simulation?
Hard28Which THREE of the following are considered 'Collection' techniques?
Easy29During a simulation, you notice a process spawning child processes from 'wmic.exe'. What is this technique often used for?
Medium30Which of the following is considered an 'Execution' tactic in the MITRE ATT&CK framework?
Easy31Which action constitutes 'Discovery' as defined by the MITRE ATT&CK framework?
Easy32Which TWO of the following are examples of 'Initial Access' tactics?
Easy33An attacker uses 'T1133 External Remote Services' to gain access. What does this involve?
Hard34Which of these is a 'Defense Evasion' technique?
Easy35Which THREE of the following are considered 'Execution' techniques?
Medium36Which THREE of the following are 'Privilege Escalation' techniques?
Hard37Which THREE of the following are common 'Exfiltration' techniques?
Easy38Which TWO of the following are examples of 'Persistence' tactics?
Medium39You detect an adversary attempting to clear Windows Event Logs using 'wevtutil cl'. This falls under which tactic?
MediumOther domains
All CCOA exam domains
Frequently asked questions
- What does the Adversarial Tactics domain cover on the CCOA exam?
- Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 39 Adversarial Tactics questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Adversarial Tactics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.