CCOA Adversarial Tactics Practice Question
You are reviewing logs in Splunk and identify a suspicious process spawning 'cmd.exe' from 'wsmprovhost.exe'. Which MITRE ATT&CK tactic does this behavior most directly align with?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lateral Movement
The spawning of a command shell from a remote management process is a classic indicator of Lateral Movement using remote execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Credential Access
Why it's wrong here
Credential access focuses on obtaining account names and passwords.
- ✗
Exfiltration
Why it's wrong here
Exfiltration is the process of stealing data from the network.
- ✓
Lateral Movement
Why this is correct
Using WinRM/PowerShell Remoting to execute commands is a primary technique for Lateral Movement.
- ✗
Persistence
Why it's wrong here
Persistence involves maintaining access, not necessarily moving laterally.
About these practice questions
Courseiva writes every CCOA question from scratch — 203 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official ISACA exam blueprint
This CCOA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCOA exam.