
Certified Cybersecurity Operations Analyst
Domain 4Objective 3
Forensic and Malware Analysis CCOA Practice Questions (Page 1)
Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
9concepts
34%of the exam
Questions 1–5
- 1
Which of the following should be included in a malware analysis report to make it actionable?
Select an answer first - 2
A malware analyst is analyzing a new ransomware sample. The analyst needs to identify the encryption algorithm used and extract the encryption key if possible. Which combination of tools is most appropriate for this task?
Select an answer first - 3
A forensic analyst is examining a compromised Windows workstation. The investigation reveals that a malicious executable was downloaded from a suspicious URL and executed, creating a scheduled task that runs at logon. Which finding is the most direct indicator of persistence?
Select an answer first - 4
A malware analyst is examining a new, unknown binary. The analyst has limited time and needs to produce actionable IOCs quickly. The binary appears to be packed, and static analysis reveals little. Which approach is most efficient to obtain IOCs?
Select an answer first - 5
Which tool is commonly used to extract indicators of compromise (IOCs) from a malware sample?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.