
Certified Cybersecurity Operations Analyst
Domain 3Objective 4
Attack Types CCOA Practice Questions (Page 3)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
10%of the exam
Questions 11–15
- 11
A security analyst is reviewing logs and notices that an attacker attempted to log in to an account using a list of common passwords such as 'password', '123456', and 'admin'. The attempts were made sequentially. Which type of password attack is this?
Select an answer first - 12
A software vendor releases a security patch for a vulnerability in their email server product. Within hours, attackers begin exploiting the vulnerability in the wild, even though no public exploit code was released. Which type of attack is this?
Select an answer first - 13
Why are zero-day exploits particularly significant in the attack lifecycle?
Select an answer first - 14
A hospital's IT department discovers that a nurse has been accessing patient records for celebrities who are not under their care. The nurse claims they were just curious and did not share the information. Which type of insider threat does this represent?
Select an answer first - 15
A company's authentication logs show a high number of failed login attempts for a single user account, with passwords tried in a sequential pattern (e.g., 'password1', 'password2', 'password3'). The account has a lockout policy after 5 failed attempts. The attacker is bypassing the lockout by waiting for the lockout period to expire. Which countermeasure would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.