CertCrush
Back to home
Free Sample

Try CCOA - Certified Cybersecurity Operations Analyst

Try 10 questions now. No account, no card.

A free account unlocks 25 questions per course plus readiness tracking.

Get full access to CCOA - Certified Cybersecurity Operations Analyst

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

September only

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

ISACA · Exam reference

About the CCOA - Certified Cybersecurity Operations Analyst exam

CCOA is ISACA's hands-on certification for security operations analysts, covering alert triage, threat detection, incident response and asset hardening. The four-hour exam mixes 115 multiple-choice questions with 25 performance-based tasks worked inside real tools. This course follows the five official domains at their published weights.

10

Sample questions

240 min

Exam time limit

70%

Passing score

$399

Exam voucher

The Certified Cybersecurity Operations Analyst (CCOA) is ISACA's first credential aimed at the people who sit at the SOC console rather than the audit desk. Where CISA, CISM and CRISC test governance and management, CCOA tests whether you can triage an alert, read a packet capture, follow an intrusion through logs and contain it. The exam runs four hours and carries 140 items: 115 multiple-choice questions and 25 performance-based tasks completed in a live environment with tools such as Wireshark and Security Onion. ISACA scores it on a scaled range of 200 to 800, and 450 passes. The weighting is where most candidates misjudge their revision. Incident Detection and Response alone is 34 percent of the paper, and Technology Essentials is another 25 percent, so those two domains are close to six items in every ten. Adversarial Tactics, Techniques, and Procedures, the domain that sounds hardest, is worth 10 percent. Candidates who pour their study time into MITRE ATT&CK matrices and skim networking fundamentals, log formats and command-line basics tend to run out of road in the technology section. CCOA suits analysts with roughly two to three years in a security operations role, and anyone weighing it against CompTIA CySA+ for the same jobs. It also suits people who already hold an ISACA certification and want a technical credential on the same CPE cycle. This course covers all five domains in the official proportions, so the practice you do reflects the paper you sit.

Exam Domains Covered

Technology Essentials · 25%Cybersecurity Principles and Risk · 20%Adversarial Tactics, Techniques, and Procedures · 10%Incident Detection and Response · 34%Securing Assets · 11%

Exam Format & Details

140 items in four hours: 115 multiple-choice questions and 25 performance-based tasks worked in a live environment with open-source tooling. ISACA reports a scaled score from 200 to 800, and 450 is the pass mark. The voucher is $399 for ISACA members and $499 for non-members, booked through ISACA.

Why Practice Questions Matter

CCOA punishes shallow recall in a specific way: the performance-based tasks give you nothing to eliminate. You either know which Wireshark display filter isolates the traffic or you do not. Multiple-choice practice cannot replace lab time, but it closes the knowledge gaps the lab exposes, and it is the fastest way through Technology Essentials, which is a quarter of the paper and largely definitional. Working questions at the official domain weights also shows you where you are weak before exam day does, which matters on a four-hour paper you would rather not sit twice.

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CCOA - Certified Cybersecurity Operations Analyst exam — not actual exam content.

Q1.An employee resigns and leaves at 09:00. Which actions are required for the departure to count as proper deprovisioning? Choose all that apply.

  • A.Disable the user account in the directory
  • B.Revoke active sessions and issued tokens
  • C.Rotate shared credentials the leaver had knowledge of
  • D.Delete the mailbox and its contents immediately
  • E.Leave the account enabled but change the password only

Domain: Securing Assets

Q2.Staff at a firm using an authenticator app are phished through a look-alike domain that relays each one time code to the real site in real time, and several sessions are compromised. Which replacement most directly removes this attack path, and why?

  • A.SMS one time codes, because the code travels over the carrier network rather than the web
  • B.FIDO2 security keys, because the credential is bound to the genuine site's origin
  • C.Push approval prompts, because the user confirms on a separate device
  • D.A longer password with a thirty day expiry, because the phished value ages out

Domain: Securing Assets

Q3.A monitoring platform's TLS certificate expired overnight. Analysts can still reach the login page but every browser and API client now shows a trust warning or refuses the connection. What has actually failed?

  • A.Traffic is now sent in cleartext because the certificate is no longer usable
  • B.Certificate validation fails on the validity dates, so clients no longer trust the identity binding
  • C.The server's private key has been destroyed and must be regenerated before any encryption works
  • D.The certificate authority has revoked the certificate and published it to a revocation list

Domain: Securing Assets

Q4.A finance database uses full disk encryption and is reached only over TLS. An attacker phishes an accounts clerk, signs in as that clerk and exports the customer table. Which statement best explains the outcome?

  • A.Disk encryption was bypassed because the attacker obtained the volume key
  • B.TLS was stripped during the export, exposing the data on the wire
  • C.Both protections were working and neither applies to an attacker inside a valid session
  • D.The export succeeded because the disk encryption key had not been rotated on schedule

Domain: Securing Assets

Q5.An adversary records a year of encrypted sessions with a web service, then obtains the server's private key twelve months later. The recorded traffic still cannot be read. Which property of the connections explains that?

  • A.Forward secrecy, with a fresh session key negotiated and then discarded
  • B.Use of a 256 bit symmetric key rather than 128 bit
  • C.Annual expiry of the server certificate
  • D.Certificate pinning in the client applications

Domain: Securing Assets

Frequently Asked Questions

What is included in the free CCOA - Certified Cybersecurity Operations Analyst sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CCOA - Certified Cybersecurity Operations Analyst course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CCOA - Certified Cybersecurity Operations Analyst course page.

Are these official ISACA exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.

Which domains does the CCOA - Certified Cybersecurity Operations Analyst course cover?

The course covers 5 exam domains: Technology Essentials, Cybersecurity Principles and Risk, Adversarial Tactics, Techniques, and Procedures, Incident Detection and Response, Securing Assets.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.