Courseiva

CCOA · topic practice

Adversarial Tactics practice questions

Practise ISACA Certified Cybersecurity Operations Analyst (CCOA) (CCOA) Adversarial Tactics practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Adversarial Tactics

What the exam tests

What to know about Adversarial Tactics

Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Adversarial Tactics exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Adversarial Tactics questions

20 questions · select your answer, then reveal the explanation

An adversary performs a 'Pass-the-Hash' attack. Which tactic does this primarily fall under?

You are auditing an environment for 'T1083 File and Directory Discovery'. Which log source provides the most visibility into this activity?

While analyzing an EDR alert, you observe a process modifying 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. What is the primary adversary objective at this stage?

In the context of the MITRE ATT&CK framework, what distinguishes 'T1059 Command and Scripting Interpreter' from 'T1204 User Execution'?

You are configuring a YARA rule for CrowdStrike Falcon to detect Cobalt Strike Beacon traffic. Which specific technique should you look for in the process memory that indicates process hollowing?

You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?

An adversary uses 'vssadmin.exe delete shadows /all /quiet' during an attack. Which tactic is this technique categorized under?

You are configuring Microsoft Defender for Endpoint. Which feature is most effective against 'T1566 Phishing'?

Which action constitutes 'Discovery' as defined by the MITRE ATT&CK framework?

What is the purpose of 'T1027 Obfuscated Files or Information'?

Which of the following is considered an 'Execution' tactic in the MITRE ATT&CK framework?

You are reviewing a Purple Team exercise involving 'T1003 OS Credential Dumping'. What is the most reliable way to detect credential dumping via LSASS process access?

What is the primary difference between a Red Team and a Blue Team in a security simulation?

Question 14mediummultiple choice
Read the full DNS explanation →

You see a process performing DNS queries for unusually long subdomains. Which tactic is the adversary likely exercising?

You detect an adversary attempting to clear Windows Event Logs using 'wevtutil cl'. This falls under which tactic?

Which technique is most effective for an adversary to perform 'T1078 Valid Accounts'?

What is the primary goal of the 'Command and Control' (C2) tactic?

Which of these is a typical 'Lateral Movement' technique?

You are implementing threat hunting for 'T1562 Impair Defenses'. Which activity are you searching for?

What is the primary function of a 'C2 Beacon'?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Adversarial Tactics sessions

Start a Adversarial Tactics only practice session

Every question in these sessions is drawn from the Adversarial Tactics domain — nothing else.

Related practice questions

Related CCOA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCOA exam test about Adversarial Tactics?
Adversarial Tactics questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Adversarial Tactics questions in a focused session?
Yes — the session launcher on this page draws every question from the Adversarial Tactics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCOA topics?
Use the topic links above to move to related areas, or go back to the CCOA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCOA exam covers. They are not copied from any real exam or dump site.