
Certified Cybersecurity Operations Analyst
Domain 3Objective 1
Attack Vectors CCOA Practice Questions (Page 4)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
10%of the exam
Questions 16–20
- 16
A company's security team discovers that an attacker has been capturing Wi-Fi traffic in a coffee shop across the street from the office. The attacker successfully obtained credentials for a user who was connected to the corporate VPN. The VPN uses a strong encryption protocol, but the user's laptop was also connected to a legacy application that sends credentials in plaintext over the local network. Which attack vector was most likely used, and what is the most effective mitigation?
Select an answer first - 17
What is the defining characteristic of a supply chain attack?
Select an answer first - 18
A security analyst is investigating a data breach. The analyst discovers that an attacker connected to the corporate network by exploiting a weak WPA2 password on a wireless access point. Once on the network, the attacker used a tool to capture traffic and obtain a user's credentials in plaintext from an unencrypted application. Which two attack vectors were combined in this attack?
Select an answer first - 19
Which web-based attack vector involves injecting malicious SQL code into a web application's input field to manipulate the database?
Select an answer first - 20
Which web-based attack vector involves injecting malicious scripts into web pages that are then executed in the browsers of other users?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.