CCOA Cyber Analyst Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q1Which phase of the Cyber Kill Chain involves an attacker gathering information about the target organization?
✓ Correct answer: D. Reconnaissance
Reconnaissance is the first phase of the Cyber Kill Chain where attackers collect information about their targets through various methods such as scanning networks, social engineering, or open-source intelligence gathering.
Q2What technique do threat actors commonly use to maintain persistence after gaining initial access to a system?
✓ Correct answer: C. Creating backdoors
Creating backdoors is a common persistence technique that allows attackers to maintain access to compromised systems even if their initial access point is discovered and remediated.
Q3Which of the following best describes a watering hole attack?
✓ Correct answer: B. Compromising websites frequently visited by the target to deliver malware
A watering hole attack involves compromising websites that target victims are known to visit, rather than attacking them directly. This allows attackers to infect specific groups of users who trust these legitimate websites.
Q4What is the primary purpose of lateral movement in an attack sequence?
✓ Correct answer: A. To gain access to additional systems within the network after initial compromise
After gaining initial access, attackers use lateral movement to expand their control by moving from one compromised system to others within the network, searching for valuable assets or higher privileges.
Q5Which of the following frameworks categorizes adversary tactics and techniques to help organizations understand attack methodologies?
✓ Correct answer: D. MITRE ATT&CK
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations, providing a framework for understanding how threat actors operate.
Q6What type of malware delivery vector involves exploiting vulnerabilities in legitimate websites to infect visitors?
✓ Correct answer: C. Drive-by download
Drive-by downloads occur when users visit compromised websites that contain malicious code that automatically downloads and executes without the user's knowledge or consent by exploiting browser or plugin vulnerabilities.
Q7Which technique involves an attacker using a compromised email account to trick recipients into believing an email is legitimate?
✓ Correct answer: B. Business Email Compromise
Business Email Compromise (BEC) involves attackers compromising or spoofing business email accounts to conduct unauthorized transfers of funds, steal data, or gain access to other systems by exploiting established trust relationships.
Q8What is the primary goal of a threat actor's exfiltration procedures?
✓ Correct answer: A. To transfer stolen data out of the target network while avoiding detection
The primary goal of exfiltration is to transfer stolen data out of the target network to an attacker-controlled location while avoiding detection by security systems.
Q9Which attack technique involves capturing authentication credentials as they pass between client and server?
✓ Correct answer: D. Man-in-the-Middle attack
Man-in-the-Middle attacks involve intercepting network traffic between two parties, allowing attackers to eavesdrop and capture sensitive information like credentials without either party knowing.
Q10What technique do attackers use to evade detection by modifying their malware's signature or behavior?
✓ Correct answer: C. Polymorphic malware
Polymorphic malware continuously changes its code and signature to appear different each time it runs, making it difficult for signature-based detection systems to identify it as malicious.
Use the free CCOA Cyber Analyst Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.