
Certified Cybersecurity Operations Analyst
Domain 3Objective 3
Threat Intelligence Sources CCOA Practice Questions (Page 2)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
10%of the exam
Questions 6–10
- 6
A healthcare organization is considering joining a Health-ISAC to share threat intelligence. They are concerned about the sensitivity of sharing their own incident data. What should they consider?
Select an answer first - 7
What is the purpose of an Information Sharing and Analysis Center (ISAC)?
Select an answer first - 8
How is OSINT typically used in threat intelligence?
Select an answer first - 9
A company is considering subscribing to a commercial threat intelligence feed. The feed offers comprehensive coverage of multiple threat actor groups and provides context-rich reports, but it is expensive. The company's budget is limited. What is the most important factor to evaluate before purchasing?
Select an answer first - 10
An analyst is comparing two threat intelligence sources for a critical alert. Source A is a commercial feed with a reputation for high accuracy, but it updates every 6 hours. Source B is a real-time OSINT feed from a well-known researcher, but it occasionally publishes unverified indicators. The alert involves a fast-spreading worm. Which source should the analyst prioritize for immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.