
Certified Cybersecurity Operations Analyst
Domain 3Objective 4
Attack Types CCOA Practice Questions (Page 1)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
10%of the exam
Questions 1–5
- 1
Which web attack involves injecting malicious scripts into a website that then execute in the browsers of other users?
Select an answer first - 2
Which of the following is an example of a malicious insider threat?
Select an answer first - 3
What is the primary goal of a Denial of Service (DoS) attack?
Select an answer first - 4
An online gaming company is experiencing intermittent outages where players cannot connect to the game servers. The network team observes a massive volume of UDP traffic flooding the servers from thousands of different IP addresses worldwide. The traffic appears to be from compromised IoT devices. Which type of attack is this?
Select an answer first - 5
An organization's security team discovers that a file named 'invoice.pdf.exe' was downloaded by an employee and executed. After execution, the malware created a backdoor and allowed remote access to the system. Which type of malware is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.