
Certified Cybersecurity Operations Analyst
Domain 3Objective 5
Cyber Attack Stages CCOA Practice Questions (Page 5)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
10%of the exam
Questions 21–25
- 21
A security analyst is reviewing a timeline of a breach. The analyst sees the following events: (1) an attacker scans the network for open ports, (2) the attacker sends a phishing email with a malicious attachment, (3) the attachment exploits a vulnerability in the email client, (4) the attacker installs a backdoor, (5) the attacker establishes a C2 channel, and (6) the attacker exfiltrates data. Which stage is missing from this timeline?
Select an answer first - 22
After exploiting a vulnerability in a web application, an attacker uploads a web shell to the server. The web shell allows the attacker to execute commands on the server and is designed to survive a server reboot. Which stage of the cyber attack lifecycle is the attacker performing?
Select an answer first - 23
A threat actor is planning an attack on a target organization. The actor has identified that the organization uses a specific email gateway that is known to block attachments with certain file extensions. The actor creates a malicious file with a double extension (e.g., 'invoice.pdf.exe') to bypass the gateway. Which stage of the cyber attack lifecycle is the actor in, and what is the primary purpose of the double extension?
Select an answer first - 24
Which of the following is an example of an action on objectives?
Select an answer first - 25
A security team is analyzing a recent breach. They find that the attacker first scanned the network for open ports, then crafted a custom exploit for a specific vulnerability, and finally sent a phishing email with a malicious attachment. Which sequence of cyber attack stages does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.