Free CCOA sample questions
Real questions from the Certified Cybersecurity Operations Analyst practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
While investigating a potential web server compromise, you discover the following log entry in the Apache access logs: `192.168.1.50 - - [10/Feb/2025:14:23:45 +0000] "GET /search.php?q=%27%20OR%201=1;-- HTTP/1.1" 200 4523` Which type of attack is indicated by this log entry?
You are configuring a new cloud-based SIEM to ingest logs from various sources. To ensure the integrity and confidentiality of the log data in transit, which protocol combination should be prioritized for log forwarding?
Which TWO of the following are primary components of the MITRE ATT&CK framework that an analyst would use to map observed adversary behavior? (Select TWO)
A financial organization is implementing a Data Loss Prevention (DLP) solution. The CISO mandates that all credit card numbers must be detected and blocked if they are sent via email. Which specific detection technique should the DLP system utilize to accurately identify valid credit card numbers while minimizing false positives?
During a forensic investigation, you need to capture the state of active network connections and running processes from a live Windows server suspected of being compromised. Which tool would be MOST appropriate for capturing this volatile data?
True or False: In a containerized environment utilizing Kubernetes, the default 'flat' network model allows all pods to communicate with each other regardless of which namespace they are in, unless Network Policies are explicitly defined to restrict traffic.
A security analyst is tuning a SIEM rule designed to detect brute-force attacks. The current rule triggers an alert if 5 failed login attempts occur within 1 minute from a single IP. The analyst notices a high volume of false positives from a legacy application that retries connections aggressively. What is the BEST approach to reduce false positives while maintaining security visibility?
Case Study: GlobalFinCorp Incident GlobalFinCorp, a multinational financial services firm, has detected suspicious activity in their environment. The SOC received an alert from their EDR solution indicating that `powershell.exe` was executed with a long, encoded command line on a workstation in the HR department. Upon further analysis, the analyst discovers the workstation had visited a URL from an email claiming to be an invoice. Shortly after, the EDR recorded network connections to a suspicious IP address on port 443, followed by the creation of a scheduled task named 'WinUpdateHelper' running a binary from a temporary directory. Based on the scenario, what is the most likely purpose of the 'WinUpdateHelper' scheduled task?
Case Study: GlobalFinCorp Incident (Continued) Following the identification of the compromised HR workstation, the Incident Response team initiates the containment phase. The affected workstation contains sensitive but not critical data. Which of the following is the MOST appropriate immediate containment action to prevent lateral movement while preserving evidence for forensic analysis?
10 more free samples are waiting
Create a free account to unlock the whole CCOA sample bank, or get full access to all 270 practice questions in the simulator.