CCOA · domain
Incident Detection And Response
Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Incident Detection And Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Detection And Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Detection And Response
Incident Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Detection And Response exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Detection And Response questions (77)
Click any question to see the full explanation, or start a practice session above.
You are configuring a Splunk Enterprise Security notable event action. Which setting ensures the notable event remains in the 'In Progress' state until a specific analyst manually updates the status?
Medium2When performing containment of a compromised endpoint in CrowdStrike Falcon, which feature should you use to prevent the adversary from using the machine to move laterally while still allowing incident responders to pull memory dumps?
Easy3Which THREE types of network logs are most effective for identifying a data breach?
Medium4You are investigating a suspicious login in Okta. Which log field should be analyzed to determine if the session originated from an anonymized VPN or Tor exit node?
Medium5You are investigating a suspected data exfiltration incident. You need to analyze network traffic captured in a PCAP file. Which tool is the industry standard for performing deep packet inspection and protocol analysis during this investigation?
Hard6You are analyzing a PCAP file and see numerous 'ICMP Echo Request' packets with unusually large payloads. What is this likely indicative of?
Medium7A SIEM alert indicates a 'Golden Ticket' attack. What is the primary indicator of this attack in the logs?
Medium8In the context of the NIST Incident Response lifecycle, which phase involves the root cause analysis and the documentation of lessons learned?
Easy9Which TWO sources are used to populate threat intelligence feeds for incident detection?
Medium10Which TWO of the following Windows log types are most useful for detecting lateral movement?
Hard11You are investigating an EDR alert showing suspicious PowerShell execution. You need to identify the parent process that spawned the malicious script. Which tool or view would best allow you to visualize this process tree?
Medium12During a triage process, you need to identify the process tree of a suspicious PowerShell execution on a Windows host using Sysmon. Which Event ID should you filter for?
Easy13During an investigation, you discover a malicious cron job on a Linux server. Which directory is the primary location for user-specific cron tasks?
Easy14A CISO asks for a list of indicators that should be monitored in the SIEM to detect potential account takeover attempts. Which THREE indicators are most relevant?
Medium15An incident response team is performing containment on a compromised Linux server that is part of a containerized environment. Given that the container is running in a Kubernetes cluster, which action is the most appropriate initial containment step to preserve the volatile memory for forensics while preventing further data exfiltration?
Medium16Which THREE types of data are typically found in a full forensic disk image?
Hard17In a Linux system, which tool is used to identify open network connections and the specific process ID (PID) associated with them?
Hard18Which TWO of the following are essential components of an effective Incident Response Plan (IRP)?
Easy19In a Palo Alto Networks environment, you need to identify if a specific internal host is beaconing to a command-and-control server. Which log type provides the necessary data?
Hard20You are investigating a potential credential harvesting site. Which tool is best suited to safely inspect the site without triggering a potential infection?
Medium21Which TWO tools are commonly used for memory forensic analysis?
Medium22You are managing an incident where an adversary is utilizing a 'Living off the Land' (LotL) technique. Which log source is most critical to detect this activity?
Medium23While investigating an incident in Google Workspace, you notice suspicious file sharing. Which log type should be queried to see which files were shared externally by a specific user?
Hard24In the context of the NIST Incident Response lifecycle, which phase involves the identification of the root cause?
Easy25Which THREE techniques do attackers use to maintain persistence on a Windows host?
Hard26When using Wireshark to investigate a data exfiltration incident, you want to filter for TCP streams involving a specific internal IP that are larger than 1MB. How is this achieved?
Hard27A security appliance flags a high volume of traffic from a single internal host to a series of random external IP addresses. This is a classic indicator of which activity?
Medium28Which type of evidence is collected to prove that a specific individual was responsible for an action on a system?
Easy29Which of the following activities is best categorized as an 'eradication' step in the incident response lifecycle?
Easy30During a Microsoft Sentinel incident investigation, you notice that a specific alert triggered by a custom analytic rule is creating too many false positives due to a noisy service account. You want to exclude this account without disabling the entire rule. What is the most effective approach?
Hard31A phishing simulation resulted in a user clicking a link. What is the next logical step in the incident response process?
Easy32You are using an ELK Stack (Elasticsearch, Logstash, Kibana) for incident response. You have identified a time-based spike in traffic. What is the most efficient way to query for the top 10 unique source IP addresses for a specific destination over the last hour using Kibana Discover?
Hard33A security analyst is triaging an alert about an unauthorized login from an unusual country. What is the first priority in the response workflow?
Easy34After an incident, you need to preserve the volatile memory of a compromised machine. What is the correct order of operations according to the Order of Volatility?
Easy35A security analyst is configuring an alert in Splunk Enterprise Security to detect potential brute force attacks. The analyst must identify the specific notable event aggregate field that prevents the creation of duplicate alerts for the same source IP over a defined time window. Which field should be utilized?
Medium36Which TWO of the following are true regarding the use of hashing in digital forensics?
Medium37Which THREE steps are part of the 'Preparation' phase of incident response?
Hard38You are configuring a 'Watchlist' in Sentinel to detect when a specific list of known malicious IPs interact with your environment. What is the correct method to map this watchlist to an analytics rule?
Medium39Which THREE of the following are common sources for SIEM data ingestion to assist in incident detection?
Medium40You are auditing a Linux server for persistence mechanisms. Which file is commonly used by attackers to hide malicious code that executes upon every user login?
Hard41What is the primary goal of the 'Eradication' phase in incident response?
Easy42You are investigating a suspicious process on Windows. You see it is running from 'C:\ProgramData'. Which tool allows you to check if the process signature is valid?
Hard43During a forensic analysis, you find a suspicious file that was renamed to look like a system file. What is the most reliable way to identify its true nature?
Hard44During the post-incident recovery phase, which TWO actions are essential to ensure the environment is returned to a secure state?
Medium45When performing digital forensics on a volatile memory dump, which THREE artifacts should you prioritize to identify evidence of fileless malware?
Hard46When conducting digital forensics on a volatile memory dump using the Volatility Framework, which TWO plugins would be most effective in identifying malicious kernel-mode rootkits?
Hard47When drafting an incident report, what is the most important element to include for the executive summary?
Easy48During an incident response engagement involving a ransomware attack, the team decides to isolate the affected endpoint using an EDR solution. What is the expected behavior of the EDR tool during the 'network isolation' process?
Medium49Which THREE phases of the incident response lifecycle involve the most interaction with stakeholders?
Easy50Which THREE behaviors are characteristic of a potential data exfiltration attempt?
Medium51Which TWO documents are essential to provide to a forensic investigator?
Easy52Which THREE indicators should an analyst monitor to identify a potential web server compromise?
Easy53You are configuring a Splunk Enterprise Security (ES) Correlation Search to detect potential brute-force activity. You need to ensure the search generates a notable event only when the threshold of 10 failed logins occurs within a 5-minute window for a specific user. Which Correlation Search attribute should be modified?
Medium54You are investigating a potential insider threat. Which log is most useful for tracking file deletion activity on a Windows file server?
Medium55A user reports they cannot access a shared drive following a suspected ransomware infection. What is the immediate containment action according to standard incident response best practices?
Easy56When classifying a security incident using the NIST SP 800-61 framework, which phase is focused on identifying the precursors and indicators of an attack?
Easy57Which TWO of the following actions are considered best practices during the 'Containment' phase of an incident response workflow?
Medium58You are monitoring a network and detect a large number of ARP requests from a single host targeting the entire subnet. This is a sign of what?
Medium59Which TWO actions should be taken if an incident is confirmed to involve sensitive PII?
Hard60You are analyzing an incident where a user's machine was compromised via a malicious document. Which Windows log indicates that a macro was executed?
Hard61In an Azure environment, you detect a malicious actor performing 'Pass-the-Token' attacks. Which sign-in log detail confirms this?
Hard62While using Microsoft Sentinel, you observe that incidents are not triggering for brute force attempts despite a KQL rule being enabled. What is the most likely cause related to the 'Incident Settings' configuration?
Hard63You are analyzing an endpoint and suspect a fileless malware attack. Which of the following is the most likely location for the malicious script to reside?
Medium64You are investigating a PowerShell-based attack. The attacker is using Base64 encoded commands. Which command line switch often indicates the use of encoded code?
Hard65While investigating a web server breach, you find malicious PHP web shells. What is the most effective way to identify the source of the upload?
Hard66When a workstation is compromised, why is it recommended to isolate it rather than turning it off?
Easy67What is a 'False Positive' in the context of SIEM alerting?
Easy68When analyzing a memory dump using Volatility 3, which plugin is most effective for detecting code injection in a suspicious process?
Hard69Which THREE factors should be considered when assessing the severity of a security incident?
Easy70A security analyst is investigating a suspected beaconing behavior in network traffic logs. The traffic consistently shows small, periodic connections to an external IP. Which statistical analysis method is most effective for identifying this pattern within high-volume PCAP or NetFlow data?
Hard71Which TWO actions are required to properly secure a compromised user account during the eradication phase?
Hard72Which type of log provides the most granular detail regarding local account creation on a Windows Server?
Easy73You are performing a digital forensic image of a SATA drive. Which tool is standard for creating a bit-stream image while ensuring data integrity via a hash verification?
Medium74A SIEM has triggered an alert for 'Excessive Failed Login Attempts' followed by a 'Successful Login'. Which technique is this most likely attempting to detect?
Medium75You are investigating an alert in CrowdStrike Falcon. To determine if a file was moved laterally after its initial execution, which feature provides the most accurate visualization?
Medium76During a digital forensics investigation of a Windows host, an analyst suspects an attacker used PowerShell 'Fileless' execution. Which artifact within the Windows Event Logs would provide the most definitive evidence of the specific command line arguments used during the execution?
Hard77You are reviewing AWS CloudTrail logs to investigate an unauthorized modification of an S3 bucket policy. Which event name should you search for?
MediumOther domains
All CCOA exam domains
Frequently asked questions
- What does the Incident Detection And Response domain cover on the CCOA exam?
- Incident Detection And Response questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 77 Incident Detection And Response questions in the CCOA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Detection And Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.