
Certified Cybersecurity Operations Analyst
Domain 3Objective 1
Attack Vectors CCOA Practice Questions (Page 1)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
10%of the exam
Questions 1–5
- 1
An employee accidentally sends an email containing a spreadsheet of customer PII to the wrong recipient because the autocomplete feature selected a similar-looking email address. The email was not encrypted. Which type of insider threat does this incident represent?
Select an answer first - 2
Why are zero-day exploits particularly dangerous as attack vectors?
Select an answer first - 3
A company uses a third-party SaaS application for HR management. The SaaS vendor announces a data breach that exposed employee records. An investigation reveals that the attacker compromised the vendor's development environment and injected malicious code into a routine software update, which was then deployed to all customers. The company's own security controls were not bypassed. Which attack vector best describes this incident, and what is the most effective preventive measure for the company?
Select an answer first - 4
Which attack vector exploits the lack of encryption in wireless networks to intercept data?
Select an answer first - 5
What is the primary goal of a phishing email that contains a malicious link?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.