Certified Cybersecurity Operations Analyst Free Sample Questions

20 free sample questions270 in the full practice test

Try simulator

CCOA Sample Questions

  1. Question 1

    A SOC analyst is reviewing network traffic logs and observes a pattern of communication where internal hosts are attempting to initiate connections to a known external command and control (C2) server over port 443. The connections are short, periodic, and consistent in size. Based on the provided flow diagram, which phase of the Cyber Kill Chain does this activity most likely represent?

    Answer and explanation

    Correct answer: B

    The activity described—internal hosts initiating periodic connections (beaconing) to an external server—is characteristic of the Command and Control (C2) phase. In this phase, compromised systems communicate with the attacker to receive instructions or exfiltrate data. Exploitation involves the actual vulnerability trigger, Delivery is sending the weaponized bundle, and Actions on Objectives happens after C2 is established.

    flowchart LR Attacker((Attacker)) -->|1. Recon| Target Attacker -->|2. Weaponize| Payload Attacker -->|3. Deliver| Target Target -->|4. Exploit| System System -->|5. Install| Malware Malware |6. C2 Beaconing| C2Server[C2 Server] Malware -->|7. Actions| Objectives style C2Server fill:#f96,stroke:#333,stroke-width:4px
  2. Question 2

    While investigating a potential web server compromise, you discover the following log entry in the Apache access logs:

    192.168.1.50 - - [10/Feb/2025:14:23:45 +0000] "GET /search.php?q=%27%20OR%201=1;-- HTTP/1.1" 200 4523

    Which type of attack is indicated by this log entry?

    Answer and explanation

    Correct answer: B

    The log entry shows a URL-encoded string %27%20OR%201=1;--, which decodes to ' OR 1=1;--. This is a classic SQL Injection payload used to bypass authentication or retrieve all records from a database by making the query condition always true. XSS would typically involve script tags ( ), and Directory Traversal would involve ../ patterns.

  3. Question 3

    You are configuring a new cloud-based SIEM to ingest logs from various sources. To ensure the integrity and confidentiality of the log data in transit, which protocol combination should be prioritized for log forwarding?

    Answer and explanation

    Correct answer: C

    Syslog over TLS (Transport Layer Security), typically using TCP port 6514, provides both encryption (confidentiality) and reliability (TCP). Standard Syslog uses UDP/514 which is unencrypted and unreliable (fire-and-forget), while TCP/514 adds reliability but lacks encryption.

  4. Question 4

    Multiple answers

    Which TWO of the following are primary components of the MITRE ATT&CK framework that an analyst would use to map observed adversary behavior? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Tactics represent the 'Why' of an attack technique—the adversary's tactical goal (e.g., Initial Access, Persistence).

    Techniques represent the 'How'—the specific method used to achieve a tactical goal (e.g., Phishing, Scheduled Task).

  5. Question 5

    A financial organization is implementing a Data Loss Prevention (DLP) solution. The CISO mandates that all credit card numbers must be detected and blocked if they are sent via email. Which specific detection technique should the DLP system utilize to accurately identify valid credit card numbers while minimizing false positives?

    Answer and explanation

    Correct answer: B

    The Luhn Algorithm (or Mod 10 algorithm) is the standard checksum formula used to validate a variety of identification numbers, including credit card numbers. While Regex can find patterns of digits, it cannot verify if the number is mathematically valid, leading to high false positives. The Luhn check ensures the digits form a valid potential card number.

  6. Question 6

    During a forensic investigation, you need to capture the state of active network connections and running processes from a live Windows server suspected of being compromised. Which tool would be MOST appropriate for capturing this volatile data?

    Answer and explanation

    Correct answer: A

    FTK Imager (or similar tools like DumpIt) is designed to capture volatile memory (RAM) where active network connections and running processes reside. While it can also image disks, its ability to capture live memory is key here. Wireshark captures packets, not process lists. Autopsy is for analysis of dead disk images. dd is a raw imaging tool typically used for disks.

  7. Question 7

    True or False: In a containerized environment utilizing Kubernetes, the default 'flat' network model allows all pods to communicate with each other regardless of which namespace they are in, unless Network Policies are explicitly defined to restrict traffic.

    Answer and explanation

    Correct answer: A

    This is True. By default, Kubernetes employs a flat networking model where all pods can communicate with all other pods across the cluster without NAT. To restrict this traffic and implement micro-segmentation, administrators must explicitly define and apply Network Policies.

  8. Question 8

    A security analyst is tuning a SIEM rule designed to detect brute-force attacks. The current rule triggers an alert if 5 failed login attempts occur within 1 minute from a single IP. The analyst notices a high volume of false positives from a legacy application that retries connections aggressively. What is the BEST approach to reduce false positives while maintaining security visibility?

    Answer and explanation

    Correct answer: C

    The best approach is to create a targeted exception (whitelisting or suppression) for the specific known benign source (the legacy app) while keeping the strict rule active for all other sources. Increasing the global threshold would reduce visibility into actual attacks. Disabling the rule leaves the organization vulnerable.

  9. Question 9

    Case Study: GlobalFinCorp Incident

    GlobalFinCorp, a multinational financial services firm, has detected suspicious activity in their environment. The SOC received an alert from their EDR solution indicating that powershell.exe was executed with a long, encoded command line on a workstation in the HR department.

    Upon further analysis, the analyst discovers the workstation had visited a URL from an email claiming to be an invoice. Shortly after, the EDR recorded network connections to a suspicious IP address on port 443, followed by the creation of a scheduled task named 'WinUpdateHelper' running a binary from a temporary directory.

    Based on the scenario, what is the most likely purpose of the 'WinUpdateHelper' scheduled task?

    Answer and explanation

    Correct answer: B

    The creation of a scheduled task is a classic mechanism for Persistence. It ensures that the malicious code runs automatically upon system reboot or at scheduled intervals, allowing the attacker to maintain access to the compromised system even if the initial process is terminated or the computer is restarted.

  10. Question 10

    Case Study: GlobalFinCorp Incident (Continued)

    Following the identification of the compromised HR workstation, the Incident Response team initiates the containment phase. The affected workstation contains sensitive but not critical data.

    Which of the following is the MOST appropriate immediate containment action to prevent lateral movement while preserving evidence for forensic analysis?

    Answer and explanation

    Correct answer: B

    Isolating the host via EDR or network switch (VLAN quarantine) effectively stops communication with the C2 server and prevents lateral movement, while keeping the system powered on. This preserves volatile memory (RAM) evidence that would be lost if the machine were powered off.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 270 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon