CCOA Cyber Analyst Prep practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.
Q21Which incident response phase involves restoring systems to normal operations and ensuring no residual threats remain?
✓ Correct answer: D. Recovery
The recovery phase focuses on bringing affected systems back to normal operation while ensuring they are free from compromise and residual threats.
Q22What is the primary purpose of an incident response playbook?
✓ Correct answer: C. To provide standardized procedures for handling specific types of incidents
Incident response playbooks provide standardized, documented procedures for handling specific types of security incidents, ensuring consistency and completeness in the response process.
Q23During incident triage, which of the following is the MOST important factor to assess first?
✓ Correct answer: B. Scope and impact of the incident
The scope and impact of an incident should be assessed first during triage to understand how widespread the incident is and what critical systems or data might be affected, which helps prioritize response efforts.
Q24Which of the following is NOT typically part of the containment phase of incident response?
✓ Correct answer: A. Performing root cause analysis
Root cause analysis is performed during the post-incident analysis phase, not during containment. Containment focuses on limiting the damage and preventing further spread of the incident.
Q25Which document typically defines roles, responsibilities, and procedures for responding to security incidents?
✓ Correct answer: D. Incident Response Plan
An Incident Response Plan (IRP) formally defines the roles, responsibilities, and procedures that should be followed when responding to security incidents.
Q26What is the purpose of maintaining a chain of custody during incident response?
✓ Correct answer: C. To ensure evidence integrity and admissibility in legal proceedings
Chain of custody documentation ensures evidence integrity by tracking who handled evidence, when, and why, which is crucial if the incident leads to legal proceedings.
Q27Which tool is BEST suited for collecting and analyzing log data from multiple sources during incident investigation?
✓ Correct answer: B. SIEM (Security Information and Event Management)
SIEM (Security Information and Event Management) systems are specifically designed to collect, correlate, and analyze log data from multiple sources, making them ideal for incident investigation.
Q28During which phase of incident response should system backups be created before making changes?
✓ Correct answer: A. Containment
Creating system backups before making changes is a critical step in the containment phase to preserve evidence and allow for recovery if containment actions have unintended consequences.
Q29What is an Indicator of Compromise (IoC)?
✓ Correct answer: D. Forensic evidence suggesting a security breach has occurred
Indicators of Compromise are forensic artifacts or evidence that suggest a system security breach or intrusion has occurred, such as unusual outbound network traffic or unexpected registry changes.
Q30Which of the following is a key component of post-incident analysis?
✓ Correct answer: C. Conducting lessons learned sessions
Lessons learned sessions identify what went well and what could be improved in the incident response process, helping to enhance future responses.
Use the free CCOA Cyber Analyst Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.