Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 3Objective 6

Exploit Techniques CCOA Practice Questions (Page 2)

Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
6concepts
10%of the exam

Questions 6–10

  1. 6foundation · easy

    A user receives a malicious PDF that, when opened, exploits a vulnerability in the PDF reader to install malware. This is best classified as which type of exploit?

    Select an answer first
  2. 7expert · hard

    A penetration tester has identified a critical vulnerability in a web application that allows remote code execution. The tester's objective is to demonstrate the maximum business impact. The tester has a low-privileged shell on the web server. The tester notices that the web server is a member of a domain and that the domain controller is reachable. Which post-exploitation action would demonstrate the highest business impact, and why?

    Select an answer first
  3. 8application · easy

    After compromising a workstation, an attacker installs a small program that will automatically restart and run every time the system boots. The attacker's goal is to maintain access to the system even after a reboot. Which post-exploitation action is the attacker performing?

    Select an answer first
  4. 9expert · hard

    An incident responder is analyzing a compromised server. The responder finds evidence that the attacker exploited a remote vulnerability to gain a foothold. The attacker then created a scheduled task that runs a script every hour to check for commands from a command-and-control server. The attacker also used stolen credentials to access a file server and copy sensitive documents. Which two post-exploitation actions are being demonstrated?

    Select an answer first
  5. 10foundation · easy

    A user visits a legitimate website that has been compromised. Without clicking anything, malicious code runs in the browser and exploits a vulnerability. This is best described as which delivery method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.