ISACA
Free ISACA CCOA Practice Questions
The CCOA - Certified Cybersecurity Operations Analyst exam is up to 140 questions in 240 minutes, and the voucher costs $399. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 5 exam domains, each with a full explanation. Free to try, no account required.
CCOA is ISACA's hands-on certification for security operations analysts, covering alert triage, threat detection, incident response and asset hardening. The four-hour exam mixes 115 multiple-choice questions with 25 performance-based tasks worked inside real tools. This course follows the five official domains at their published weights.
Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.
10
Sample questions
240 min
Exam time limit
70%
Practice pass mark
$399
Exam voucher
About the CCOA - Certified Cybersecurity Operations Analyst Exam
The Certified Cybersecurity Operations Analyst (CCOA) is ISACA's first credential aimed at the people who sit at the SOC console rather than the audit desk. Where CISA, CISM and CRISC test governance and management, CCOA tests whether you can triage an alert, read a packet capture, follow an intrusion through logs and contain it. The exam runs four hours and carries 140 items: 115 multiple-choice questions and 25 performance-based tasks completed in a live environment with tools such as Wireshark and Security Onion. ISACA scores it on a scaled range of 200 to 800, and 450 passes. The weighting is where most candidates misjudge their revision. Incident Detection and Response alone is 34 percent of the paper, and Technology Essentials is another 25 percent, so those two domains are close to six items in every ten. Adversarial Tactics, Techniques, and Procedures, the domain that sounds hardest, is worth 10 percent. Candidates who pour their study time into MITRE ATT&CK matrices and skim networking fundamentals, log formats and command-line basics tend to run out of road in the technology section. CCOA suits analysts with roughly two to three years in a security operations role, and anyone weighing it against CompTIA CySA+ for the same jobs. It also suits people who already hold an ISACA certification and want a technical credential on the same CPE cycle. This course covers all five domains in the official proportions, so the practice you do reflects the paper you sit.
Exam Domains Covered
Exam Format & Details
140 items in four hours: 115 multiple-choice questions and 25 performance-based tasks worked in a live environment with open-source tooling. ISACA reports a scaled score from 200 to 800, and 450 is the pass mark. The voucher is $399 for ISACA members and $499 for non-members, booked through ISACA.
Why Practice Questions Matter
CCOA punishes shallow recall in a specific way: the performance-based tasks give you nothing to eliminate. You either know which Wireshark display filter isolates the traffic or you do not. Multiple-choice practice cannot replace lab time, but it closes the knowledge gaps the lab exposes, and it is the fastest way through Technology Essentials, which is a quarter of the paper and largely definitional. Working questions at the official domain weights also shows you where you are weak before exam day does, which matters on a four-hour paper you would rather not sit twice.
Try CCOA - Certified Cybersecurity Operations Analyst
Try 10 questions now. No account, no card.
A free account unlocks 25 questions per course plus readiness tracking.
Get full access to CCOA - Certified Cybersecurity Operations Analyst
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
Lifetime · all courses
$29.99
One payment · future courses included
30 seconds, then straight to checkout.
Try 2 performance tasks free
Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real CCOA - Certified Cybersecurity Operations Analyst exam, marked with partial credit.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CCOA - Certified Cybersecurity Operations Analyst exam, not actual exam content.
Q1.An employee resigns and leaves at 09:00. Which actions are required for the departure to count as proper deprovisioning? Choose all that apply.
- A.Disable the user account in the directory
- B.Revoke active sessions and issued tokens
- C.Rotate shared credentials the leaver had knowledge of
- D.Delete the mailbox and its contents immediately
- E.Leave the account enabled but change the password only
Domain: Securing Assets
Q2.Staff at a firm using an authenticator app are phished through a look-alike domain that relays each one time code to the real site in real time, and several sessions are compromised. Which replacement most directly removes this attack path, and why?
- A.SMS one time codes, because the code travels over the carrier network rather than the web
- B.FIDO2 security keys, because the credential is bound to the genuine site's origin
- C.Push approval prompts, because the user confirms on a separate device
- D.A longer password with a thirty day expiry, because the phished value ages out
Domain: Securing Assets
Q3.A monitoring platform's TLS certificate expired overnight. Analysts can still reach the login page but every browser and API client now shows a trust warning or refuses the connection. What has actually failed?
- A.Traffic is now sent in cleartext because the certificate is no longer usable
- B.Certificate validation fails on the validity dates, so clients no longer trust the identity binding
- C.The server's private key has been destroyed and must be regenerated before any encryption works
- D.The certificate authority has revoked the certificate and published it to a revocation list
Domain: Securing Assets
Q4.A finance database uses full disk encryption and is reached only over TLS. An attacker phishes an accounts clerk, signs in as that clerk and exports the customer table. Which statement best explains the outcome?
- A.Disk encryption was bypassed because the attacker obtained the volume key
- B.TLS was stripped during the export, exposing the data on the wire
- C.Both protections were working and neither applies to an attacker inside a valid session
- D.The export succeeded because the disk encryption key had not been rotated on schedule
Domain: Securing Assets
Q5.An adversary records a year of encrypted sessions with a web service, then obtains the server's private key twelve months later. The recorded traffic still cannot be read. Which property of the connections explains that?
- A.Forward secrecy, with a fresh session key negotiated and then discarded
- B.Use of a 256 bit symmetric key rather than 128 bit
- C.Annual expiry of the server certificate
- D.Certificate pinning in the client applications
Domain: Securing Assets
Q6.A client is deciding whether to accept a server's TLS certificate without a warning. Which checks must all succeed for the certificate to be accepted? Choose all that apply.
- A.The current date falls inside the certificate's validity period
- B.The requested host name is covered by the subject alternative names
- C.The chain resolves through any intermediates to a trusted root in the client's trust store
- D.The public key is at least 4096 bits long
- E.The server's IP address has a matching reverse DNS record
Domain: Securing Assets
Q7.A policy states: allow access when the user's department is Finance, the device reports as compliant, the request falls inside working hours and the source country is the United Kingdom. Which access control model is in use?
- A.Role-based access control
- B.Discretionary access control
- C.Attribute-based access control
- D.Mandatory access control
Domain: Securing Assets
Q8.A user cannot reach any resource, and ipconfig on the endpoint reports the address 169.254.18.77 with mask 255.255.0.0. What has failed?
- A.DNS resolution is failing for the configured resolver
- B.DHCP did not answer, so the host self-assigned a link-local address
- C.An access control list on the default gateway is blocking the host
- D.Another machine on the subnet holds the same static address
Domain: Technology Essentials
Q9.Host 10.10.20.45 is configured with the mask 255.255.255.0. Which address is the broadcast address for its subnet?
- A.10.10.20.0
- B.10.10.20.1
- C.10.10.20.254
- D.10.10.20.255
Domain: Technology Essentials
Q10.A contract is signed with a private key and distributed with the signature attached. Which properties does verifying that signature with the matching public key establish? Choose all that apply.
- A.Authenticity of the signer
- B.Integrity of the signed content
- C.Non-repudiation by the signer
- D.Confidentiality of the document contents
- E.Availability of the document to all recipients
Domain: Securing Assets
CCOA - Certified Cybersecurity Operations Analyst guides & exam news
ISACA CCOA Explained: Exam Domains, Cost and Is It Worth It in 2026?
ISACA's CCOA is a new hands-on cert for SOC analysts, built around performance-based questions and open-source tools. Here is what the exam covers, what it costs, how it compares to CySA+, and whether it is worth taking in 2026.
How to Pass the ISACA AAISM Exam in 2026: An 8-Week AI Security Management Study Plan
A week-by-week AAISM study plan built around the real 31/31/38 domain split. Covers the CISM or CISSP prerequisite, how long to revise, and the scaled 450 pass mark on ISACA's 90-question AI security management exam.
Best AI Governance Certification in 2026: AIGP vs AAIA vs AAISM vs ISO 42001 (And What the AI Act Delay Changes)
Four credentials now compete for the same AI governance job adverts, and they are not interchangeable. Here is what AIGP, ISACA AAIA, ISACA AAISM and the ISO 42001 Lead Auditor route actually cost, who can sit them, and which one matches your role.
Frequently Asked Questions
Does the CCOA - Certified Cybersecurity Operations Analyst course include performance-based questions?
Yes. The CCOA - Certified Cybersecurity Operations Analyst course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.
What is included in the free CCOA - Certified Cybersecurity Operations Analyst sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CCOA - Certified Cybersecurity Operations Analyst course?
The full CCOA - Certified Cybersecurity Operations Analyst course includes 400 practice questions and 20 performance-based tasks, covering all 5 exam domains. Every question carries a full explanation for the right answer and the wrong ones.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CCOA - Certified Cybersecurity Operations Analyst course cover?
The course covers 5 exam domains: Technology Essentials, Cybersecurity Principles and Risk, Adversarial Tactics, Techniques, and Procedures, Incident Detection and Response, Securing Assets.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.