Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 4Objective 1

Detection and Analysis CCOA Practice Questions (Page 4)

Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
8concepts
34%of the exam

Questions 16–20

  1. 16expert · hard

    A SOC is overwhelmed by a high volume of alerts, most of which are false positives. The team wants to reduce alert fatigue without missing real incidents. They have a SIEM that can ingest logs from multiple sources and support custom correlation rules. Which approach would be most effective in reducing false positives while maintaining detection capability?

    Select an answer first
  2. 17application · medium

    An analyst is reviewing network flow data and notices a large amount of data being transferred from a database server to an external IP address on port 443 (HTTPS). The database server is not supposed to initiate outbound connections. The external IP is not in any threat intelligence feeds. What should the analyst do first?

    Select an answer first
  3. 18foundation · easy

    Which log source is most useful for correlating a user's activity across multiple systems?

    Select an answer first
  4. 19application · medium

    During an incident investigation, an analyst discovers that a compromised host communicated with an external IP address that is listed in a threat intelligence feed as a command-and-control (C2) server. The analyst also notices that the host made DNS queries for a domain that is algorithmically generated. Which combination of indicators provides the strongest evidence of a coordinated attack?

    Select an answer first
  5. 20foundation · easy

    An analyst receives an alert from a SIEM indicating a high number of failed logins. What is the first step in validating this alert?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.