HomeCCOA Cyber Analyst PrepQuestions 11–20
CCOA Cyber Analyst PrepPart 2 of 3

CCOA Cyber Analyst Prep Exam Questions & Answers 2026 (11–20)

CCOA Cyber Analyst Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CCOA Cyber Analyst Prep questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q11Which of the following is a common method for threat actors to escalate privileges after gaining initial access?

    • AImplementing network segmentation
    • BExploiting unpatched vulnerabilities
    • CInstalling anti-virus software
    • DEnabling multi-factor authentication
    Show answer

    ✓ Correct answer: B. Exploiting unpatched vulnerabilities

    Exploiting unpatched vulnerabilities is a common method for privilege escalation, as these security flaws can allow attackers to gain administrative or system-level access from a lower-privileged account.

  2. Q12What technique involves hackers using legitimate administrative tools to conduct malicious activities?

    • ALiving off the land
    • BSocial engineering
    • CBrute force attacks
    • DDNS tunneling
    Show answer

    ✓ Correct answer: A. Living off the land

    Living off the land involves using legitimate system tools and features (like PowerShell, WMI, or PsExec) for malicious purposes, making attacks harder to detect since they leverage trusted system processes.

  3. Q13Which of the following best describes a supply chain attack?

    • ADirectly attacking an organization's network perimeter
    • BConducting DDoS attacks against cloud service providers
    • CExploiting vulnerabilities in public-facing web applications
    • DCompromising a trusted vendor to distribute malware through legitimate software updates
    Show answer

    ✓ Correct answer: D. Compromising a trusted vendor to distribute malware through legitimate software updates

    A supply chain attack compromises software vendors or suppliers to insert malicious code into legitimate software updates or products, allowing attackers to gain access to all organizations using those products.

  4. Q14What is the purpose of data staging in the exfiltration process?

    • ATo permanently delete the original data
    • BTo modify system logs to hide evidence
    • CTo collect and prepare stolen data in a central location before transferring it out of the network
    • DTo encrypt the stolen data
    Show answer

    ✓ Correct answer: C. To collect and prepare stolen data in a central location before transferring it out of the network

    Data staging involves collecting and organizing stolen data in a central location within the victim's network before exfiltration, allowing attackers to efficiently transfer larger amounts of data and potentially avoid detection.

  5. Q15Which threat actor capability allows attackers to maintain control over compromised systems?

    • ASocial engineering
    • BCommand and Control infrastructure
    • CVulnerability scanning
    • DPassword cracking
    Show answer

    ✓ Correct answer: B. Command and Control infrastructure

    Command and Control infrastructure enables attackers to remotely communicate with and control compromised systems, allowing them to issue commands, update malware, and manage their attack operations.

  6. Q16What technique do attackers use to hide communication with their command and control servers?

    • ADNS tunneling
    • BNetwork segmentation
    • CIntrusion prevention
    • DFirewall implementation
    Show answer

    ✓ Correct answer: A. DNS tunneling

    DNS tunneling encapsulates other protocols within DNS queries and responses to establish covert communication channels, making malicious traffic appear as legitimate DNS traffic to evade detection.

  7. Q17Which attack vector involves manipulating a user into taking actions that benefit the attacker?

    • ASQL injection
    • BBuffer overflow
    • CCross-site scripting
    • DSocial engineering
    Show answer

    ✓ Correct answer: D. Social engineering

    Social engineering manipulates users through psychological tactics rather than technical means, tricking them into performing actions or divulging confidential information that aids the attacker's objectives.

  8. Q18What is the primary purpose of credential dumping in an attack sequence?

    • ATo identify vulnerabilities in applications
    • BTo encrypt sensitive data on the system
    • CTo extract stored credentials from a compromised system for use in lateral movement
    • DTo create new administrative accounts
    Show answer

    ✓ Correct answer: C. To extract stored credentials from a compromised system for use in lateral movement

    Credential dumping extracts passwords, hashes, or authentication tokens from a system's memory or storage, allowing attackers to obtain valid credentials for lateral movement and privilege escalation.

  9. Q19Which technique involves attackers maintaining long-term, stealthy access to a target network?

    • ACrypto-jacking
    • BAdvanced Persistent Threat (APT)
    • CDistributed Denial of Service (DDoS)
    • DRansomware attack
    Show answer

    ✓ Correct answer: B. Advanced Persistent Threat (APT)

    Advanced Persistent Threats involve sophisticated attackers who establish a long-term presence within a target network, focusing on remaining undetected while slowly mapping the network and extracting valuable data over time.

  10. Q20What technique do attackers use to identify potential entry points into a target network?

    • APort scanning
    • BData exfiltration
    • CLateral movement
    • DPrivilege escalation
    Show answer

    ✓ Correct answer: A. Port scanning

    Port scanning systematically probes network ports to discover available services, potential vulnerabilities, and open communication channels that could serve as entry points for attackers.

Free practice here. Timed mocks when you are ready.

Use the free CCOA Cyber Analyst Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.