
Certified Cybersecurity Operations Analyst
Domain 3Objective 6
Exploit Techniques CCOA Practice Questions (Page 2)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
6concepts
10%of the exam
Questions 6–10
- 6
A user receives a malicious PDF that, when opened, exploits a vulnerability in the PDF reader to install malware. This is best classified as which type of exploit?
Select an answer first - 7
A penetration tester has identified a critical vulnerability in a web application that allows remote code execution. The tester's objective is to demonstrate the maximum business impact. The tester has a low-privileged shell on the web server. The tester notices that the web server is a member of a domain and that the domain controller is reachable. Which post-exploitation action would demonstrate the highest business impact, and why?
Select an answer first - 8
After compromising a workstation, an attacker installs a small program that will automatically restart and run every time the system boots. The attacker's goal is to maintain access to the system even after a reboot. Which post-exploitation action is the attacker performing?
Select an answer first - 9
An incident responder is analyzing a compromised server. The responder finds evidence that the attacker exploited a remote vulnerability to gain a foothold. The attacker then created a scheduled task that runs a script every hour to check for commands from a command-and-control server. The attacker also used stolen credentials to access a file server and copy sensitive documents. Which two post-exploitation actions are being demonstrated?
Select an answer first - 10
A user visits a legitimate website that has been compromised. Without clicking anything, malicious code runs in the browser and exploits a vulnerability. This is best described as which delivery method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.