Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 4Objective 3

Forensic and Malware Analysis CCOA Practice Questions (Page 5)

Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
9concepts
34%of the exam

Questions 21–24

  1. 21application · medium

    A malware analyst needs to observe the behavior of a suspicious executable in a safe environment. The analyst wants to see what files it creates, what registry keys it modifies, and what network connections it makes. Which approach is most appropriate?

    Select an answer first
  2. 22application · medium

    During an incident response, an analyst must collect forensic data from a compromised Linux server. The server is still running, and the analyst needs to preserve evidence in a forensically sound manner. Which approach is most appropriate?

    Select an answer first
  3. 23foundation · easy

    Why is a sandbox environment used for dynamic malware analysis?

    Select an answer first
  4. 24application · medium

    A forensic analyst has completed the examination of a data breach and must write a report that may be used in legal proceedings. Which practice is most important for the report to be legally defensible?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CCOA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.