
Certified Cybersecurity Operations Analyst
Domain 3Objective 3
Threat Intelligence Sources CCOA Practice Questions (Page 5)
Part of the Domain 3: Adversarial Tactics, Techniques, and Procedures domain, which accounts for 10% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
10%of the exam
Questions 21–25
- 21
Which of the following is an example of government-led threat intelligence sharing?
Select an answer first - 22
A company is evaluating a commercial feed that provides excellent context and reports, but its indicators are often already published by free OSINT sources. The feed is significantly more expensive than the free sources. What is the most important consideration in deciding whether to subscribe?
Select an answer first - 23
A company is choosing between two commercial threat intelligence feeds. Feed X provides real-time indicators but has a higher false positive rate. Feed Y provides indicators with a 1-hour delay but has a very low false positive rate. The company's SOC is understaffed and cannot handle many false positives. Which feed should they choose?
Select an answer first - 24
A security operations center (SOC) wants to build a threat intelligence program with limited staff. They need to prioritize sources that provide the most value with the least manual effort. Which approach is most effective?
Select an answer first - 25
A security team is designing a threat intelligence program. They want to include sources that provide both external context and internal visibility. Which combination of sources best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.