
Certified Cybersecurity Operations Analyst
Domain 4Objective 1
Detection and Analysis CCOA Practice Questions (Page 2)
Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
8concepts
34%of the exam
Questions 6–10
- 6
Which monitoring tool is specifically designed to capture and analyze network packets?
Select an answer first - 7
Which analytical approach is best suited for detecting a previously unknown malware infection that exhibits unusual network behavior?
Select an answer first - 8
A SOC analyst is investigating an alert that was triggered by a SIEM correlation rule. The rule is designed to detect a specific attack pattern. The analyst finds that the alert was triggered by a series of events that match the rule, but upon further investigation, the events are found to be part of a legitimate business process. What should the analyst do?
Select an answer first - 9
What is the primary purpose of threat intelligence in incident response?
Select an answer first - 10
A security analyst is reviewing an alert about a suspicious email that was received by a user. The email contains a link to a website that is known to host malware. The analyst wants to determine if the user clicked the link. Which data source would provide the most direct evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.