
Certified Cybersecurity Operations Analyst
Domain 3Objective 5
Cyber Attack Stages CCOA Practice Questions (Page 4)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
10%of the exam
Questions 16–20
- 16
An attacker has crafted a malicious macro-enabled Word document. The attacker has learned from open-source intelligence that the target organization frequently shares documents with a specific partner company. The attacker sends the document via email, posing as an employee of that partner company. Which attack stage is the attacker performing?
Select an answer first - 17
A penetration tester is simulating an attack against a client's environment. The tester has identified that the client's employees frequently open email attachments. The tester creates a malicious PDF that exploits a known vulnerability in the client's PDF reader software. In which stage of the cyber attack lifecycle is the tester operating?
Select an answer first - 18
What is the primary purpose of the installation stage in a cyber attack?
Select an answer first - 19
Which of the following is a common method used in the weaponization stage?
Select an answer first - 20
What is the purpose of the command and control (C2) stage in a cyber attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.