Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 3Objective 6

Exploit Techniques CCOA Practice Questions (Page 5)

Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
6concepts
10%of the exam

Questions 21–25

  1. 21application · medium

    A security team is hardening a Windows application server that hosts a custom application known to have a memory corruption vulnerability. The team wants to implement a mitigation that makes it harder for an attacker to predict the memory addresses of system libraries and thus more difficult to exploit the buffer overflow. Which mitigation technique should the team enable?

    Select an answer first
  2. 22foundation · easy

    An attacker exploits a vulnerability in a web server that is directly accessible from the internet, without any user interaction. This is best classified as which type of exploit?

    Select an answer first
  3. 23application · medium

    A software developer is reviewing a vulnerability report for a legacy web application. The report states that an attacker can submit a specially crafted input string in a search field that causes the application to execute arbitrary SQL commands against the backend database. Which exploit execution mechanism is being described, and which mitigation would be most effective to prevent this specific attack?

    Select an answer first
  4. 24application · medium

    An incident responder is analyzing a compromised workstation. The responder finds that the attacker used a vulnerability in a local service to gain SYSTEM privileges. The attacker then used those privileges to disable the antivirus software. Which exploit category and post-exploitation action are being demonstrated?

    Select an answer first
  5. 25application · medium

    A security analyst is investigating an alert where an attacker exploited a vulnerability in a web server to gain a shell. The analyst then observes the attacker using the compromised server to scan and connect to other servers on the internal network. Which exploit category was used for the initial compromise, and which post-exploitation action is the attacker performing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.