Skip to content

CCOA Practice Questions

Prepare for CCOA with more than an answer.

270 questions in the full set20 sample questionsUpdated Jan 31, 2026
Exam fee
$399 USD
Level
Operations Analyst
Valid for
3 years
Domains covered on the exam 5
  1. Technology Essentials25%
  2. Cybersecurity Principles and Risk20%
  3. Adversarial Tactics, Techniques, and Procedures10%
  4. Incident Detection and Response34%
  5. Securing Assets11%
  1. 1

    Which of the following describes a 'False Negative' in the context of an Intrusion Detection System (IDS)?

    Show answer details

    Correct answer: B

    A False Negative occurs when the system incorrectly identifies malicious activity as benign—meaning it fails to fire an alert for a real attack. This is the most dangerous type of error. A False Positive is alerting on benign traffic.

  2. 2

    You are auditing the IAM configuration for a cloud environment. You find that several developers have been assigned the 'Owner' role for the production subscription to facilitate easier debugging. Which security principle is being violated?

    Show answer details

    Correct answer: A

    The Principle of Least Privilege states that users should only be granted the minimum level of access necessary to perform their job functions. Granting 'Owner' (full control) rights to developers for debugging violates this, as they likely only need 'Reader' or specific 'Contributor' rights.

  3. 3

    A SOC analyst observes a sudden spike in outbound traffic on port 53 (DNS) from a single internal workstation. The traffic consists of TXT record queries to a high-entropy domain name (e.g., a1b2c3d4.evil-domain.com). What is the most likely explanation for this activity?

    Show answer details

    Correct answer: A

    This pattern is highly indicative of DNS Tunneling. Attackers encode stolen data into the subdomains of DNS queries (often TXT or A records) to bypass firewalls, as DNS is often allowed outbound. The authoritative DNS server for evil-domain.com receives the queries and decodes the data.

  4. 4

    Select TWO methods that can effectively be used to validate the integrity of a downloaded software package before installation. (Select TWO)

    Show answer details

    Correct answer: B, D

    Digital signatures provide both authenticity (it came from the vendor) and integrity (it hasn't been altered). Windows executables often carry these signatures.

    Comparing the calculated hash of the downloaded file with the official hash provided by the vendor ensures the file has not been modified in transit.

  5. 5

    You are investigating a Linux server and suspect a malicious process is running. Which command would be MOST effective for listing all running processes, including those owned by other users, to identify the suspicious activity?

    Show answer details

    Correct answer: D

    ps aux is the standard Linux command to display a snapshot of all running processes. 'a' shows processes for all users, 'u' displays the user/owner, and 'x' shows processes not attached to a terminal (daemons). ls -la lists files, netstat lists network connections, top is dynamic but ps aux is preferred for a complete static list to pipe/search.

  6. 6

    A SOC analyst is reviewing network traffic logs and observes a pattern of communication where internal hosts are attempting to initiate connections to a known external command and control (C2) server over port 443. The connections are short, periodic, and consistent in size. Based on the provided flow diagram, which phase of the Cyber Kill Chain does this activity most likely represent?

    Show answer details

    Correct answer: C

    The activity described—internal hosts initiating periodic connections (beaconing) to an external server—is characteristic of the Command and Control (C2) phase. In this phase, compromised systems communicate with the attacker to receive instructions or exfiltrate data. Exploitation involves the actual vulnerability trigger, Delivery is sending the weaponized bundle, and Actions on Objectives happens after C2 is established.

    flowchart LR Attacker((Attacker)) -->|1. Recon| Target Attacker -->|2. Weaponize| Payload Attacker -->|3. Deliver| Target Target -->|4. Exploit| System System -->|5. Install| Malware Malware |6. C2 Beaconing| C2Server[C2 Server] Malware -->|7. Actions| Objectives style C2Server fill:#f96,stroke:#333,stroke-width:4px
  7. 7

    While investigating a potential web server compromise, you discover the following log entry in the Apache access logs:

    192.168.1.50 - - [10/Feb/2025:14:23:45 +0000] "GET /search.php?q=%27%20OR%201=1;-- HTTP/1.1" 200 4523

    Which type of attack is indicated by this log entry?

    Show answer details

    Correct answer: A

    The log entry shows a URL-encoded string %27%20OR%201=1;--, which decodes to ' OR 1=1;--. This is a classic SQL Injection payload used to bypass authentication or retrieve all records from a database by making the query condition always true. XSS would typically involve script tags ( ), and Directory Traversal would involve ../ patterns.

  8. 8

    You are configuring a new cloud-based SIEM to ingest logs from various sources. To ensure the integrity and confidentiality of the log data in transit, which protocol combination should be prioritized for log forwarding?

    Show answer details

    Correct answer: A

    Syslog over TLS (Transport Layer Security), typically using TCP port 6514, provides both encryption (confidentiality) and reliability (TCP). Standard Syslog uses UDP/514 which is unencrypted and unreliable (fire-and-forget), while TCP/514 adds reliability but lacks encryption.

  9. 9

    Which TWO of the following are primary components of the MITRE ATT&CK framework that an analyst would use to map observed adversary behavior? (Select TWO)

    Show answer details

    Correct answer: A, D

    Tactics represent the 'Why' of an attack technique—the adversary's tactical goal (e.g., Initial Access, Persistence).

    Techniques represent the 'How'—the specific method used to achieve a tactical goal (e.g., Phishing, Scheduled Task).

  10. 10

    A financial organization is implementing a Data Loss Prevention (DLP) solution. The CISO mandates that all credit card numbers must be detected and blocked if they are sent via email. Which specific detection technique should the DLP system utilize to accurately identify valid credit card numbers while minimizing false positives?

    Show answer details

    Correct answer: B

    The Luhn Algorithm (or Mod 10 algorithm) is the standard checksum formula used to validate a variety of identification numbers, including credit card numbers. While Regex can find patterns of digits, it cannot verify if the number is mathematically valid, leading to high false positives. The Luhn check ensures the digits form a valid potential card number.

Create an account to continue.