CCOA Cyber Analyst Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q11Which of the following is a common method for threat actors to escalate privileges after gaining initial access?
✓ Correct answer: B. Exploiting unpatched vulnerabilities
Exploiting unpatched vulnerabilities is a common method for privilege escalation, as these security flaws can allow attackers to gain administrative or system-level access from a lower-privileged account.
Q12What technique involves hackers using legitimate administrative tools to conduct malicious activities?
✓ Correct answer: A. Living off the land
Living off the land involves using legitimate system tools and features (like PowerShell, WMI, or PsExec) for malicious purposes, making attacks harder to detect since they leverage trusted system processes.
Q13Which of the following best describes a supply chain attack?
✓ Correct answer: D. Compromising a trusted vendor to distribute malware through legitimate software updates
A supply chain attack compromises software vendors or suppliers to insert malicious code into legitimate software updates or products, allowing attackers to gain access to all organizations using those products.
Q14What is the purpose of data staging in the exfiltration process?
✓ Correct answer: C. To collect and prepare stolen data in a central location before transferring it out of the network
Data staging involves collecting and organizing stolen data in a central location within the victim's network before exfiltration, allowing attackers to efficiently transfer larger amounts of data and potentially avoid detection.
Q15Which threat actor capability allows attackers to maintain control over compromised systems?
✓ Correct answer: B. Command and Control infrastructure
Command and Control infrastructure enables attackers to remotely communicate with and control compromised systems, allowing them to issue commands, update malware, and manage their attack operations.
Q16What technique do attackers use to hide communication with their command and control servers?
✓ Correct answer: A. DNS tunneling
DNS tunneling encapsulates other protocols within DNS queries and responses to establish covert communication channels, making malicious traffic appear as legitimate DNS traffic to evade detection.
Q17Which attack vector involves manipulating a user into taking actions that benefit the attacker?
✓ Correct answer: D. Social engineering
Social engineering manipulates users through psychological tactics rather than technical means, tricking them into performing actions or divulging confidential information that aids the attacker's objectives.
Q18What is the primary purpose of credential dumping in an attack sequence?
✓ Correct answer: C. To extract stored credentials from a compromised system for use in lateral movement
Credential dumping extracts passwords, hashes, or authentication tokens from a system's memory or storage, allowing attackers to obtain valid credentials for lateral movement and privilege escalation.
Q19Which technique involves attackers maintaining long-term, stealthy access to a target network?
✓ Correct answer: B. Advanced Persistent Threat (APT)
Advanced Persistent Threats involve sophisticated attackers who establish a long-term presence within a target network, focusing on remaining undetected while slowly mapping the network and extracting valuable data over time.
Q20What technique do attackers use to identify potential entry points into a target network?
✓ Correct answer: A. Port scanning
Port scanning systematically probes network ports to discover available services, potential vulnerabilities, and open communication channels that could serve as entry points for attackers.
Use the free CCOA Cyber Analyst Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.