Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 3Objective 6

Exploit Techniques CCOA Practice Questions (Page 1)

Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
6concepts
10%of the exam

Questions 1–5

  1. 1application · medium

    A security team is reviewing the mitigations for a legacy application that has a known buffer overflow vulnerability. The team cannot patch the application immediately. Which mitigation technique would make it more difficult for an attacker to execute arbitrary code by preventing the CPU from executing code in memory regions marked as non-executable?

    Select an answer first
  2. 2application · medium

    A penetration tester is documenting an exploit chain. The tester first sends a malicious input to a web application that causes a buffer overflow in a C library, allowing the tester to execute code. The tester then uses this code execution to create a new user account with administrative privileges. Which two concepts are being demonstrated in this chain?

    Select an answer first
  3. 3application · medium

    A developer is fixing a bug in a C++ application where a pointer to a memory object is used after the object has been freed. An attacker could exploit this bug to execute arbitrary code. Which exploit execution mechanism is being described, and which mitigation would be most effective to prevent this specific bug from being exploited?

    Select an answer first
  4. 4application · medium

    A user reports that after visiting a compromised website, their browser automatically downloaded and executed a malicious file without any user interaction. The malware then installed a backdoor. Which exploit delivery method and exploit category best describe this attack?

    Select an answer first
  5. 5foundation · easy

    Which sequence best represents the general process of exploiting a vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.