Courseiva
Back to ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CCOA
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CCOA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which THREE of the following are 'Command and Control' techniques?

Question 2mediummulti select
Full question →

Which TWO of the following are examples of 'Persistence' tactics?

Question 3hardmulti select
Full question →

Which THREE of the following are 'Privilege Escalation' techniques?

Question 4easymulti select
Full question →

Which TWO of the following are examples of 'Detection' capabilities in the NIST CSF?

Question 5mediummulti select
Full question →

Which THREE of the following are considered 'Execution' techniques?

Question 6hardmulti select
Full question →

Which THREE of the following are common 'Impact' techniques?

Question 7easymulti select
Full question →

Which TWO of the following are examples of 'Initial Access' tactics?

Question 8easymulti select
Full question →

Which THREE of the following are considered 'Collection' techniques?

Question 9mediummulti select
Full question →

Which TWO of the following are examples of 'Discovery' techniques?

Question 10hardmulti select
Full question →

Which TWO of the following behaviors are typical of 'Lateral Movement'?

Question 11mediummulti select
Full question →

Which THREE actions are essential to the 'Identify' function of the NIST CSF?

Question 12mediummulti select
Full question →

Which THREE items are typically included in a formal Risk Register?

Question 13hardmulti select
Full question →

Which THREE controls are considered effective 'Administrative' controls according to the NIST framework?

Question 14easymulti select
Full question →

Which TWO of the following are considered 'Credential Access' techniques?

Question 15easymulti select
Full question →

Which TWO of the following are core components of the CIA Triad?

Question 16hardmulti select
Full question →

Which TWO of the following are considered 'Technical' controls?

Question 17easymulti select
Full question →

Which TWO of the following are essential components of an effective Incident Response Plan (IRP)?

Question 18mediummulti select
Full question →

Which THREE of the following are common sources for SIEM data ingestion to assist in incident detection?

Question 19hardmulti select
Full question →

Which THREE techniques do attackers use to maintain persistence on a Windows host?

Question 20easymulti select
Full question →

Which THREE factors should be considered when assessing the severity of a security incident?

These CCOA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CCOA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.