Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Cybersecurity Operations Analyst

Domain 4Objective 2

Incident Response and Handling CCOA Practice Questions (Page 3)

Part of the Domain 4: Incident Detection and Response domain, which accounts for 34% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~32–54 in this domain), expect 11–18 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
8concepts
34%of the exam

Questions 11–15

  1. 11application · medium

    A company has just experienced a security incident. The incident response team has contained the threat and eradicated the malware. The team is now in the process of restoring systems to normal operation. According to the incident handling lifecycle, what should the team do after completing the recovery phase?

    Select an answer first
  2. 12application · medium

    An incident responder is handling a malware infection on a laptop that is connected to the corporate network. The laptop contains sensitive data and is used by a sales representative. The responder needs to contain the infection while preserving evidence for analysis. Which action should the responder take?

    Select an answer first
  3. 13application · medium

    During incident response, an analyst discovers that an attacker has been using PowerShell to run malicious scripts on a compromised workstation. The analyst needs to contain the incident while preserving evidence for a potential legal case. Which action best achieves both goals?

    Select an answer first
  4. 14foundation · easy

    During containment implementation, why is it important to preserve evidence?

    Select an answer first
  5. 15expert · hard

    A security operations center receives three incident alerts simultaneously. Alert 1: A single workstation has been infected with adware. Alert 2: A database server is being accessed by an unauthorized IP address, and the server contains sensitive customer data. Alert 3: A phishing email has been reported by one user, but no one has clicked the link. The team has limited resources. Which incident should be prioritized first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.