
Certified Cybersecurity Operations Analyst
Domain 3Objective 7
Penetration Testing CCOA Practice Questions (Page 6)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
10%of the exam
Questions 26–30
- 26
Which tool is commonly used to identify open ports and services running on a target system?
Select an answer first - 27
A penetration tester has exploited a vulnerability and gained access to a Linux server. The tester wants to escalate privileges to root. The tester has discovered that the server is running a vulnerable version of a kernel module. Which technique is MOST appropriate?
Select an answer first - 28
A penetration tester is conducting reconnaissance on a target organization. The tester wants to gather information about employees, email formats, and technology stacks WITHOUT directly interacting with the target's systems. Which technique should the tester use?
Select an answer first - 29
A penetration tester is performing reconnaissance on a target organization. The tester has gathered information from public sources and now wants to identify internal IP addresses and network topology. Which technique is MOST effective for this purpose?
Select an answer first - 30
A penetration tester is using a vulnerability scanner and identifies a potential SQL injection in a web application. The scanner reports the vulnerability as 'high' severity. Before including this finding in the report, what should the tester do to ensure accuracy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.