
Certified Cybersecurity Operations Analyst
Domain 3Objective 1
Attack Vectors CCOA Practice Questions (Page 2)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
10%of the exam
Questions 6–10
- 6
Which physical attack vector involves an attacker leaving a malware-infected USB drive in a parking lot, hoping an employee will plug it into a company computer?
Select an answer first - 7
Which credential theft technique involves an attacker recording a user's keystrokes to capture passwords?
Select an answer first - 8
Which malware delivery method involves a user visiting a compromised website that automatically downloads malware without any user interaction?
Select an answer first - 9
A web application developer receives a vulnerability scan report showing that the application's search feature is vulnerable to SQL injection. The developer is asked to fix the issue before the application is deployed. Which remediation approach directly addresses the root cause of this vulnerability?
Select an answer first - 10
Which physical attack vector involves an attacker following an authorized employee through a secured door without proper credentials?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.