
Certified Cybersecurity Operations Analyst
Domain 4Objective 2
Incident Response and Handling CCOA Practice Questions (Page 1)
Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
34%of the exam
Questions 1–5
- 1
Which action is essential for preserving the integrity of digital evidence?
Select an answer first - 2
Which containment strategy involves removing an affected system from the network to prevent further communication with other hosts?
Select an answer first - 3
A company is responding to a security incident that involves a data breach. The incident response team is working with external legal counsel and a public relations firm. The CEO wants to issue a public statement about the breach. What should the incident response team do?
Select an answer first - 4
Why is it important to document all actions taken during an incident response?
Select an answer first - 5
A security analyst detects a malware infection on a server that is part of a cluster providing a critical web service. The malware is spreading to other servers in the cluster. The analyst needs to contain the infection while minimizing downtime for the web service. Which containment action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.