
Certified Cybersecurity Operations Analyst
Domain 3Objective 4
Attack Types CCOA Practice Questions (Page 4)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
10%of the exam
Questions 16–20
- 16
A company's file server is infected with malware that encrypts all files and displays a message demanding payment in cryptocurrency to decrypt them. The malware spread to other servers on the network automatically without user interaction. Which type of malware is this?
Select an answer first - 17
An attacker calls an employee, pretending to be from IT support, and asks for their password to 'fix a network issue'. Which social engineering technique is being used?
Select an answer first - 18
Which attack type is primarily designed to disrupt the availability of a service by overwhelming it with traffic?
Select an answer first - 19
An attacker submits the following input to a login form: 'admin' OR '1'='1'. Which type of web attack is this?
Select an answer first - 20
An organization discovers software on a workstation that silently records the user's keystrokes and captures screenshots. Which malware variant best describes this software?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.