
Certified Cybersecurity Operations Analyst
Domain 3Objective 3
Threat Intelligence Sources CCOA Practice Questions (Page 3)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
10%of the exam
Questions 11–15
- 11
Which of the following is an internal threat intelligence source?
Select an answer first - 12
What is the primary role of threat intelligence sources in cybersecurity operations?
Select an answer first - 13
An analyst discovers a new malware sample hash on a public malware analysis sandbox. The sandbox report shows the malware communicates with a specific domain. What is the most appropriate use of this OSINT?
Select an answer first - 14
A company is deciding whether to join an ISAC or subscribe to a commercial feed. The ISAC offers sector-specific intelligence but requires active participation and sharing of internal data. The commercial feed offers broad coverage but is expensive. The company values both sector relevance and cost efficiency. What is the most balanced approach?
Select an answer first - 15
When evaluating a threat intelligence source, what does 'reliability' refer to?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.