
Certified Cybersecurity Operations Analyst
Domain 3Objective 1
Attack Vectors CCOA Practice Questions (Page 7)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
10%of the exam
Questions 31–35
- 31
Which network attack vector involves an attacker setting up a rogue access point that impersonates a legitimate wireless network to trick users into connecting?
Select an answer first - 32
A security team discovers that an attacker has been exploiting a vulnerability in a third-party plugin used by the company's content management system (CMS). The plugin vendor has not released a patch, and the vulnerability is not listed in any public CVE database. The attacker has been using this exploit to upload a web shell to the CMS. Which attack vector is being used, and what is the most effective immediate action?
Select an answer first - 33
A security team discovers that an attacker has exploited a previously unknown vulnerability in the company's web server software. The software vendor has not yet released a patch, and no antivirus signatures detect the exploit. Which type of attack vector does this represent?
Select an answer first - 34
A security analyst receives a report from an employee who clicked a link in an email that appeared to be from the company's IT help desk. The link led to a page that looked like the corporate single sign-on portal, but the URL was slightly misspelled. The employee entered their username and password before realizing the page was fake. The analyst checks the email headers and finds the message originated from an external domain. Which combination of attack vectors best describes what occurred?
Select an answer first - 35
An employee accidentally sends a confidential customer database to a personal email address. What type of insider threat does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.