
Certified Cybersecurity Operations Analyst
Domain 3Objective 2
Threat Actors / Agents CCOA Practice Questions (Page 1)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
10%of the exam
Questions 1–5
- 1
A company discovers that a competitor has been accessing its confidential product plans. The attacker used spear-phishing emails to compromise an employee's account and then quietly exfiltrated documents over several months. Which intention is most likely?
Select an answer first - 2
A security operations center notices an increase in ransomware attacks against small municipalities. The attacks use a new ransomware-as-a-service (RaaS) model where affiliates are recruited on underground forums. Which threat actor trend does this best illustrate?
Select an answer first - 3
Which of the following is an emerging trend in threat actor tactics?
Select an answer first - 4
Which of the following is an example of an indicator that could be used in threat actor attribution?
Select an answer first - 5
Why is threat actor attribution considered challenging in cybersecurity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.