Courseiva

CCOA · domain

Incident Detection And Response

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Incident Detection And Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

77 questions22 easy29 medium26 hard

Focused practice

Practice Incident Detection And Response questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Detection And Response

Incident Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Detection And Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Detection And Response questions (77)

Click any question to see the full explanation, or start a practice session above.

1

You are configuring a Splunk Enterprise Security notable event action. Which setting ensures the notable event remains in the 'In Progress' state until a specific analyst manually updates the status?

Medium
2

When performing containment of a compromised endpoint in CrowdStrike Falcon, which feature should you use to prevent the adversary from using the machine to move laterally while still allowing incident responders to pull memory dumps?

Easy
3

Which THREE types of network logs are most effective for identifying a data breach?

Medium
4

You are investigating a suspicious login in Okta. Which log field should be analyzed to determine if the session originated from an anonymized VPN or Tor exit node?

Medium
5

You are investigating a suspected data exfiltration incident. You need to analyze network traffic captured in a PCAP file. Which tool is the industry standard for performing deep packet inspection and protocol analysis during this investigation?

Hard
6

You are analyzing a PCAP file and see numerous 'ICMP Echo Request' packets with unusually large payloads. What is this likely indicative of?

Medium
7

A SIEM alert indicates a 'Golden Ticket' attack. What is the primary indicator of this attack in the logs?

Medium
8

In the context of the NIST Incident Response lifecycle, which phase involves the root cause analysis and the documentation of lessons learned?

Easy
9

Which TWO sources are used to populate threat intelligence feeds for incident detection?

Medium
10

Which TWO of the following Windows log types are most useful for detecting lateral movement?

Hard
11

You are investigating an EDR alert showing suspicious PowerShell execution. You need to identify the parent process that spawned the malicious script. Which tool or view would best allow you to visualize this process tree?

Medium
12

During a triage process, you need to identify the process tree of a suspicious PowerShell execution on a Windows host using Sysmon. Which Event ID should you filter for?

Easy
13

During an investigation, you discover a malicious cron job on a Linux server. Which directory is the primary location for user-specific cron tasks?

Easy
14

A CISO asks for a list of indicators that should be monitored in the SIEM to detect potential account takeover attempts. Which THREE indicators are most relevant?

Medium
15

An incident response team is performing containment on a compromised Linux server that is part of a containerized environment. Given that the container is running in a Kubernetes cluster, which action is the most appropriate initial containment step to preserve the volatile memory for forensics while preventing further data exfiltration?

Medium
16

Which THREE types of data are typically found in a full forensic disk image?

Hard
17

In a Linux system, which tool is used to identify open network connections and the specific process ID (PID) associated with them?

Hard
18

Which TWO of the following are essential components of an effective Incident Response Plan (IRP)?

Easy
19

In a Palo Alto Networks environment, you need to identify if a specific internal host is beaconing to a command-and-control server. Which log type provides the necessary data?

Hard
20

You are investigating a potential credential harvesting site. Which tool is best suited to safely inspect the site without triggering a potential infection?

Medium
21

Which TWO tools are commonly used for memory forensic analysis?

Medium
22

You are managing an incident where an adversary is utilizing a 'Living off the Land' (LotL) technique. Which log source is most critical to detect this activity?

Medium
23

While investigating an incident in Google Workspace, you notice suspicious file sharing. Which log type should be queried to see which files were shared externally by a specific user?

Hard
24

In the context of the NIST Incident Response lifecycle, which phase involves the identification of the root cause?

Easy
25

Which THREE techniques do attackers use to maintain persistence on a Windows host?

Hard
26

When using Wireshark to investigate a data exfiltration incident, you want to filter for TCP streams involving a specific internal IP that are larger than 1MB. How is this achieved?

Hard
27

A security appliance flags a high volume of traffic from a single internal host to a series of random external IP addresses. This is a classic indicator of which activity?

Medium
28

Which type of evidence is collected to prove that a specific individual was responsible for an action on a system?

Easy
29

Which of the following activities is best categorized as an 'eradication' step in the incident response lifecycle?

Easy
30

During a Microsoft Sentinel incident investigation, you notice that a specific alert triggered by a custom analytic rule is creating too many false positives due to a noisy service account. You want to exclude this account without disabling the entire rule. What is the most effective approach?

Hard
31

A phishing simulation resulted in a user clicking a link. What is the next logical step in the incident response process?

Easy
32

You are using an ELK Stack (Elasticsearch, Logstash, Kibana) for incident response. You have identified a time-based spike in traffic. What is the most efficient way to query for the top 10 unique source IP addresses for a specific destination over the last hour using Kibana Discover?

Hard
33

A security analyst is triaging an alert about an unauthorized login from an unusual country. What is the first priority in the response workflow?

Easy
34

After an incident, you need to preserve the volatile memory of a compromised machine. What is the correct order of operations according to the Order of Volatility?

Easy
35

A security analyst is configuring an alert in Splunk Enterprise Security to detect potential brute force attacks. The analyst must identify the specific notable event aggregate field that prevents the creation of duplicate alerts for the same source IP over a defined time window. Which field should be utilized?

Medium
36

Which TWO of the following are true regarding the use of hashing in digital forensics?

Medium
37

Which THREE steps are part of the 'Preparation' phase of incident response?

Hard
38

You are configuring a 'Watchlist' in Sentinel to detect when a specific list of known malicious IPs interact with your environment. What is the correct method to map this watchlist to an analytics rule?

Medium
39

Which THREE of the following are common sources for SIEM data ingestion to assist in incident detection?

Medium
40

You are auditing a Linux server for persistence mechanisms. Which file is commonly used by attackers to hide malicious code that executes upon every user login?

Hard
41

What is the primary goal of the 'Eradication' phase in incident response?

Easy
42

You are investigating a suspicious process on Windows. You see it is running from 'C:\ProgramData'. Which tool allows you to check if the process signature is valid?

Hard
43

During a forensic analysis, you find a suspicious file that was renamed to look like a system file. What is the most reliable way to identify its true nature?

Hard
44

During the post-incident recovery phase, which TWO actions are essential to ensure the environment is returned to a secure state?

Medium
45

When performing digital forensics on a volatile memory dump, which THREE artifacts should you prioritize to identify evidence of fileless malware?

Hard
46

When conducting digital forensics on a volatile memory dump using the Volatility Framework, which TWO plugins would be most effective in identifying malicious kernel-mode rootkits?

Hard
47

When drafting an incident report, what is the most important element to include for the executive summary?

Easy
48

During an incident response engagement involving a ransomware attack, the team decides to isolate the affected endpoint using an EDR solution. What is the expected behavior of the EDR tool during the 'network isolation' process?

Medium
49

Which THREE phases of the incident response lifecycle involve the most interaction with stakeholders?

Easy
50

Which THREE behaviors are characteristic of a potential data exfiltration attempt?

Medium
51

Which TWO documents are essential to provide to a forensic investigator?

Easy
52

Which THREE indicators should an analyst monitor to identify a potential web server compromise?

Easy
53

You are configuring a Splunk Enterprise Security (ES) Correlation Search to detect potential brute-force activity. You need to ensure the search generates a notable event only when the threshold of 10 failed logins occurs within a 5-minute window for a specific user. Which Correlation Search attribute should be modified?

Medium
54

You are investigating a potential insider threat. Which log is most useful for tracking file deletion activity on a Windows file server?

Medium
55

A user reports they cannot access a shared drive following a suspected ransomware infection. What is the immediate containment action according to standard incident response best practices?

Easy
56

When classifying a security incident using the NIST SP 800-61 framework, which phase is focused on identifying the precursors and indicators of an attack?

Easy
57

Which TWO of the following actions are considered best practices during the 'Containment' phase of an incident response workflow?

Medium
58

You are monitoring a network and detect a large number of ARP requests from a single host targeting the entire subnet. This is a sign of what?

Medium
59

Which TWO actions should be taken if an incident is confirmed to involve sensitive PII?

Hard
60

You are analyzing an incident where a user's machine was compromised via a malicious document. Which Windows log indicates that a macro was executed?

Hard
61

In an Azure environment, you detect a malicious actor performing 'Pass-the-Token' attacks. Which sign-in log detail confirms this?

Hard
62

While using Microsoft Sentinel, you observe that incidents are not triggering for brute force attempts despite a KQL rule being enabled. What is the most likely cause related to the 'Incident Settings' configuration?

Hard
63

You are analyzing an endpoint and suspect a fileless malware attack. Which of the following is the most likely location for the malicious script to reside?

Medium
64

You are investigating a PowerShell-based attack. The attacker is using Base64 encoded commands. Which command line switch often indicates the use of encoded code?

Hard
65

While investigating a web server breach, you find malicious PHP web shells. What is the most effective way to identify the source of the upload?

Hard
66

When a workstation is compromised, why is it recommended to isolate it rather than turning it off?

Easy
67

What is a 'False Positive' in the context of SIEM alerting?

Easy
68

When analyzing a memory dump using Volatility 3, which plugin is most effective for detecting code injection in a suspicious process?

Hard
69

Which THREE factors should be considered when assessing the severity of a security incident?

Easy
70

A security analyst is investigating a suspected beaconing behavior in network traffic logs. The traffic consistently shows small, periodic connections to an external IP. Which statistical analysis method is most effective for identifying this pattern within high-volume PCAP or NetFlow data?

Hard
71

Which TWO actions are required to properly secure a compromised user account during the eradication phase?

Hard
72

Which type of log provides the most granular detail regarding local account creation on a Windows Server?

Easy
73

You are performing a digital forensic image of a SATA drive. Which tool is standard for creating a bit-stream image while ensuring data integrity via a hash verification?

Medium
74

A SIEM has triggered an alert for 'Excessive Failed Login Attempts' followed by a 'Successful Login'. Which technique is this most likely attempting to detect?

Medium
75

You are investigating an alert in CrowdStrike Falcon. To determine if a file was moved laterally after its initial execution, which feature provides the most accurate visualization?

Medium
76

During a digital forensics investigation of a Windows host, an analyst suspects an attacker used PowerShell 'Fileless' execution. Which artifact within the Windows Event Logs would provide the most definitive evidence of the specific command line arguments used during the execution?

Hard
77

You are reviewing AWS CloudTrail logs to investigate an unauthorized modification of an S3 bucket policy. Which event name should you search for?

Medium

Frequently asked questions

What does the Incident Detection And Response domain cover on the CCOA exam?
Incident Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 77 Incident Detection And Response questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Detection And Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Incident Detection And Response Practice Questions