CCOA Sample Questions

CCOA Sample Questions & Answers

Detecting and responding to incidents is weighted heaviest, ahead of technology essentials spanning networking, cloud and programming, identity and vulnerability management, adversarial attack tactics and stages, and governance, compliance and risk.

Launch the full CCOA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Incident Detection and Response · Incident Analysis

    During a forensic investigation, you need to capture the state of active network connections and running processes from a live Windows server suspected of being compromised. Which tool would be MOST appropriate for capturing this volatile data?

    Show answer & explanation

    Correct answer: D

    FTK Imager (or similar tools like DumpIt) is designed to capture volatile memory (RAM) where active network connections and running processes reside. While it can also image disks, its ability to capture live memory is key here. Wireshark captures packets, not process lists. Autopsy is for analysis of dead disk images. dd is a raw imaging tool typically used for disks.

  2. Question 2Advanced

    Technology Essentials · Systems and Endpoints

    True or False: In a containerized environment utilizing Kubernetes, the default 'flat' network model allows all pods to communicate with each other regardless of which namespace they are in, unless Network Policies are explicitly defined to restrict traffic.

    Show answer & explanation

    Correct answer: A

    This is True. By default, Kubernetes employs a flat networking model where all pods can communicate with all other pods across the cluster without NAT. To restrict this traffic and implement micro-segmentation, administrators must explicitly define and apply Network Policies.

  3. Question 3Intermediate

    Incident Detection and Response · Detection Capabilities

    A security analyst is tuning a SIEM rule designed to detect brute-force attacks. The current rule triggers an alert if 5 failed login attempts occur within 1 minute from a single IP. The analyst notices a high volume of false positives from a legacy application that retries connections aggressively. What is the BEST approach to reduce false positives while maintaining security visibility?

    Show answer & explanation

    Correct answer: A

    The best approach is to create a targeted exception (whitelisting or suppression) for the specific known benign source (the legacy app) while keeping the strict rule active for all other sources. Increasing the global threshold would reduce visibility into actual attacks. Disabling the rule leaves the organization vulnerable.

  4. Question 4Intermediate

    Adversarial Tactics, Techniques, and Procedures · Cyber Attack Stages and Methodologies

    Case Study: GlobalFinCorp Incident

    GlobalFinCorp, a multinational financial services firm, has detected suspicious activity in their environment. The SOC received an alert from their EDR solution indicating that powershell.exe was executed with a long, encoded command line on a workstation in the HR department.

    Upon further analysis, the analyst discovers the workstation had visited a URL from an email claiming to be an invoice. Shortly after, the EDR recorded network connections to a suspicious IP address on port 443, followed by the creation of a scheduled task named 'WinUpdateHelper' running a binary from a temporary directory.

    Based on the scenario, what is the most likely purpose of the 'WinUpdateHelper' scheduled task?

    Show answer & explanation

    Correct answer: B

    The creation of a scheduled task is a classic mechanism for Persistence. It ensures that the malicious code runs automatically upon system reboot or at scheduled intervals, allowing the attacker to maintain access to the compromised system even if the initial process is terminated or the computer is restarted.

  5. Question 5Intermediate

    Incident Detection and Response · Incident Response

    Case Study: GlobalFinCorp Incident (Continued)

    Following the identification of the compromised HR workstation, the Incident Response team initiates the containment phase. The affected workstation contains sensitive but not critical data.

    Which of the following is the MOST appropriate immediate containment action to prevent lateral movement while preserving evidence for forensic analysis?

    Show answer & explanation

    Correct answer: B

    Isolating the host via EDR or network switch (VLAN quarantine) effectively stops communication with the C2 server and prevents lateral movement, while keeping the system powered on. This preserves volatile memory (RAM) evidence that would be lost if the machine were powered off.

  6. Question 6Intermediate

    Cybersecurity Principles and Risk · Risk Management

    You are reviewing the security architecture for a new cloud application. The application uses a microservices architecture where services authenticate to each other using mutual TLS (mTLS). In the context of the Zero Trust model, which principle is primarily being applied here?

    Show answer & explanation

    Correct answer: A

    Mutual TLS (mTLS) ensures that both the client and server authenticate each other for every connection. This aligns with the Zero Trust principle of 'Verify Explicitly' (or 'Never Trust, Always Verify'), ensuring that no entity is trusted solely based on network location.

  7. Question 7Beginner

    Incident Detection and Response · Incident Analysis

    A security analyst needs to verify if a suspicious file found on an endpoint communicates with known malicious domains. The analyst does not have access to a dedicated malware lab. Which of the following is the SAFEST way to analyze the file's behavior?

    Show answer & explanation

    Correct answer: D

    Uploading the file hash (not the file itself, if confidentiality is a concern, but typically the hash is safe) to a service like VirusTotal allows the analyst to see if other vendors have flagged it and view behavioral reports from automated sandboxes without executing the code locally.

  8. Question 8Intermediate

    Securing Assets · Vulnerability Management

    When conducting a vulnerability scan of a production web server, which scan configuration should be used to minimize the risk of causing a denial of service or crashing the application?

    Show answer & explanation

    Correct answer: B

    Enabling 'Safe Checks' or 'Non-intrusive' mode ensures that the scanner relies on banner grabbing and version detection rather than sending active exploit payloads that might destabilize the service. This is critical for production environments.

  9. Question 9Intermediate

    Technology Essentials · Applications and Programming

    Which of the following PowerShell commands would an analyst use to calculate the SHA-256 hash of a file named malware.exe to verify its integrity or check against threat intelligence feeds?

    Show answer & explanation

    Correct answer: B

    The Get-FileHash cmdlet is the standard PowerShell command for computing file hashes. The -Algorithm parameter specifies the hash algorithm (SHA256 is the default if not specified in newer versions, but specifying it is precise).

  10. Question 10Beginner

    Incident Detection and Response · Incident Response

    In the context of Incident Response, which phase primarily involves the removal of malicious artifacts, reimaging of compromised systems, and patching of vulnerabilities to ensure the threat is completely eliminated?

    Show answer & explanation

    Correct answer: C

    Eradication is the phase where the root cause of the incident is removed. This includes deleting malware, disabling compromised accounts, and patching vulnerabilities. Containment is about stopping the spread. Recovery is about restoring normal operations.

Ready for the real thing?

The full CCOA simulator has every exam-style question, timed mode, and instant scoring.

Go to the CCOA simulator →