
Certified Cybersecurity Operations Analyst
Domain 4Objective 1
Detection and Analysis CCOA Practice Questions (Page 1)
Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
8concepts
34%of the exam
Questions 1–5
- 1
An analyst is investigating a potential data exfiltration incident. The analyst has captured a PCAP file and notices a large amount of outbound traffic from an internal host to an external IP address on port 53 (DNS). The traffic is not typical DNS queries. What should the analyst do to confirm if this is data exfiltration?
Select an answer first - 2
Which of the following is an example of an Indicator of Attack (IoA)?
Select an answer first - 3
What is the primary function of a SIEM tool in a security operations center?
Select an answer first - 4
What is the key difference between an Indicator of Compromise (IoC) and an Indicator of Attack (IoA)?
Select an answer first - 5
A SOC analyst is reviewing an alert from the SIEM that indicates a possible malware infection on a workstation. The alert was triggered by an endpoint detection and response (EDR) tool. The analyst also sees a firewall log showing outbound traffic from that workstation to a suspicious IP address. However, the analyst notices that the EDR alert is a low-severity 'PUP' (potentially unwanted program) detection. What should the analyst do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.