Cisco Certified Support Technician (CCST) Cybersecurity practice questions
226 free questions with answers and explanations.
- 51.A security analyst is conducting a vulnerability assessment on a new custom-developed web application. The analyst wants to identify potential weaknesses in the application's source code before it is deployed to production. Which type of testing would be most effective for this purpose?Vulnerability Management
- 52.A security team is considering adopting a new approach to vulnerability assessment that focuses on identifying security flaws early in the software development lifecycle, before deployment to production. This approach aims to reduce the cost and effort of fixing vulnerabilities. Which of the following assessment types aligns with this strategy?Vulnerability Management
- 53.After a vulnerability scan identifies several critical vulnerabilities on a production server, the security team decides to apply the recommended patches during the next scheduled maintenance window. Before applying the patches, they create a full backup of the server and plan for rollback procedures. What phase of vulnerability remediation does this activity PRIMARILY represent?Vulnerability Management
- 54.A penetration tester is performing a gray-box assessment on an internal network application. The client has provided limited access to documentation and a non-privileged user account. What is the primary benefit of this approach compared to a black-box assessment for this scenario?Vulnerability Management
- 55.A security analyst is investigating a potential compromise. Logs show that an attacker exploited a known vulnerability in an unpatched web server. The vulnerability had a CVSS Base Score of 9.8 (Critical) and was publicly disclosed three months prior. The organization's vulnerability management policy states that critical vulnerabilities must be patched within 7 days of discovery. What is the MOST likely reason this vulnerability led to a breach?Vulnerability Management
- 56.A company has identified a critical vulnerability in a third-party software component that is integral to its core business application. The vendor has acknowledged the vulnerability but has not yet released a patch, stating it will take several weeks. To reduce immediate risk, the security team implements an Intrusion Prevention System (IPS) rule to block known exploit patterns targeting this specific vulnerability. What type of control is the IPS rule in this scenario?Vulnerability Management
- 57.A security analyst discovers a critical vulnerability in a proprietary application. The vendor has announced that a patch will be released in 30 days. In the meantime, the analyst implements a temporary configuration change on the application's hosting server to prevent exploitation. What is this temporary measure called?Vulnerability Management
- 58.A security auditor is performing an assessment where they have full access to the target system's configuration files, operating system details, and installed software components. This allows them to conduct a very thorough and accurate analysis without needing to guess system behaviors. What type of vulnerability assessment is being performed?Vulnerability Management
- 59.A software development company uses a version control system that meticulously tracks every change made to the source code, including who made the change, when it was made, and what exactly was modified. This system includes cryptographic hashes to ensure that no unauthorized alterations to the code can go undetected. Which security principle is primarily being upheld by this system's use of cryptographic hashes?Security Principles
- 60.A security auditor is performing a vulnerability assessment for a client. The client provides the auditor with network diagrams, system configurations, and authentication credentials for all target systems. What type of assessment methodology is the auditor employing?Vulnerability Management
- 61.A security analyst is investigating a potential compromise. Logs show that an attacker exploited a known vulnerability in a web server's content management system (CMS) that was identified in a scan two weeks prior. The vulnerability was triaged with a 'Medium' priority and remediation was scheduled for the next month. Which stage of the vulnerability management lifecycle failed in this scenario?Vulnerability Management
- 62.A new web application is being developed that handles customer financial transactions. The development team is concerned about attackers intercepting sensitive data, such as credit card numbers, as it travels between the customer's browser and the web server. Which security control would be most effective in mitigating this specific threat?Security Principles
- 63.A newly hired cybersecurity analyst is reviewing a company's asset inventory. They identify several unpatched legacy servers running critical business applications that are directly accessible from the internet. Which foundational security concept is most directly violated by the presence of these unpatched, internet-facing systems?Security Principles
- 64.A company is developing a new mobile application that will handle sensitive user data. Before deployment, they conduct thorough penetration testing and code reviews to identify and remediate vulnerabilities. This proactive approach primarily aims to address which common security threat category?Security Principles
- 65.A security team is reviewing the results of a vulnerability scan on a critical production server. The scan report indicates a 'High' severity vulnerability related to an outdated version of SSH. Due to operational constraints, immediate patching is not possible. What is the most appropriate temporary mitigation strategy to reduce the risk associated with this finding?Vulnerability Management
- 66.A security analyst is reviewing a vulnerability report for a critical web server. The report indicates a vulnerability with a Common Vulnerability Scoring System (CVSS) Base Score of 8.6. The analyst determines that the server is located in a highly secured internal network segment, accessible only by a few authorized administrators, and has robust intrusion prevention systems in place. Which CVSS metric category would be most directly influenced by these mitigating factors when calculating the final score?Vulnerability Management
- 67.A cybersecurity team has discovered a critical zero-day vulnerability in a proprietary internal application. There is no patch available from the vendor, and the development team cannot provide an immediate fix. To protect the application while a permanent solution is developed, the security team decides to isolate the application on a dedicated network segment with strict firewall rules and implement multi-factor authentication (MFA) for all access. What type of control best describes the firewall rules and MFA in this scenario?Vulnerability Management
- 68.A cybersecurity team is tasked with implementing a comprehensive security policy framework. They understand that policies alone are insufficient and must be supported by practical guidelines. Which element defines the mandatory, high-level statements that dictate the organization's overarching security philosophy and requirements?Security Principles
- 69.A cybersecurity analyst has identified a critical vulnerability in a web application. The vulnerability allows unauthenticated users to bypass login and access sensitive customer data. The development team has acknowledged the issue but states a patch will take at least two weeks to develop and deploy. Which of the following is the BEST immediate action to take to protect the data while awaiting the permanent fix?Vulnerability Management
- 70.A security team is analyzing a vulnerability report from a recent scan. One vulnerability has a Common Vulnerability Scoring System (CVSS) base score of 9.8 (Critical). However, the team knows that the affected system is isolated on a segmented network, has no direct internet access, and is only accessible by a few highly privileged administrators. How should the team interpret this CVSS score in the context of their specific environment?Vulnerability Management
- 71.A company has identified a critical vulnerability in a third-party library used by several of its internal applications. The vendor has released a patch, but applying it immediately would require significant downtime and retesting, which cannot be done until the next maintenance window in two weeks. To mitigate the risk in the interim, the security team decides to implement a temporary measure that reduces the likelihood of exploitation. What is this temporary risk reduction measure called?Vulnerability Management
- 72.A cybersecurity analyst is reviewing a vulnerability scan report that lists several high-severity vulnerabilities related to outdated software versions on critical servers. The analyst needs to prioritize which vulnerabilities to address first given limited resources and a strict compliance deadline. Which of the following factors is MOST critical in determining the immediate remediation priority?Vulnerability Management
- 73.A security auditor is reviewing an organization's access control policies. They find that several employees have been granted administrative privileges to systems even though their job roles do not require such elevated access. This directly violates which fundamental security concept?Security Principles
- 74.A network administrator notices an unusually high volume of login attempts from various IP addresses around the world targeting a single user account on their email server. These attempts are occurring rapidly and are designed to guess the password. Which type of attack is most likely occurring?Security Principles
- 75.A security analyst is reviewing a vulnerability report for a critical web application. The report highlights a SQL Injection vulnerability that could allow an attacker to extract sensitive data from the database. The development team states they cannot immediately patch the vulnerability due to a complex release cycle. To address the immediate risk, they propose implementing input validation and parameterized queries in the application layer. What type of vulnerability management action is this?Vulnerability Management
- 76.A security team is conducting a vulnerability assessment on a new server deployed in their demilitarized zone (DMZ). The team needs to identify vulnerabilities from the perspective of an attacker outside the network, without providing any credentials or internal access to the scanner. Which scanning approach should they use?Vulnerability Management
- 77.A security team has deployed a new web application firewall (WAF) to protect a critical online service. The team wants to ensure that the WAF is effectively blocking known attack patterns and preventing common web-based vulnerabilities before the service goes live. Which type of vulnerability assessment would be most appropriate for this scenario?Vulnerability Management
- 78.A manufacturing plant relies heavily on its industrial control systems (ICS) for production. An unexpected cyberattack causes these systems to shut down for several hours, leading to significant production losses. The primary security principle that was compromised in this scenario is:Security Principles
- 79.A cybersecurity analyst is performing a black-box penetration test on a new web application. During the reconnaissance phase, the analyst discovers that the application uses a common open-source library, 'FooLib v1.2.3'. What is the most effective next step for the analyst to identify potential vulnerabilities related to this library?Vulnerability Management
- 80.After a successful penetration test, a security consultant provides a client with a report detailing several high-severity vulnerabilities. The client's security team is now tasked with fixing these issues. Which stage of the vulnerability management lifecycle are they primarily engaged in?Vulnerability Management
- 81.A company's email server is experiencing a sudden and overwhelming flood of connection requests from hundreds of thousands of unique IP addresses, making the server unresponsive and preventing legitimate users from accessing their email. The requests appear to be legitimate but are designed to exhaust server resources. What type of attack is most likely occurring?Security Principles
- 82.A security analyst is reviewing a vulnerability scan report for a critical production server. The report indicates a missing security patch for the operating system that could lead to remote code execution. However, the server is isolated on a segmented network with no direct internet access and is protected by multiple layers of firewalls. Which CVSS metric should the analyst adjust to reflect this reduced exposure?Vulnerability Management
- 83.A small business is setting up its first network and wants to ensure that only authorized devices can connect to its Wi-Fi. Which security concept is primarily being addressed by implementing a strong pre-shared key (PSK) and MAC address filtering?Security Principles
- 84.A security analyst is investigating a suspected data breach. They discover that an attacker gained unauthorized access to a database by exploiting a known vulnerability in the database software that had not been patched, despite a patch being available for months. Which security principle was most directly undermined in this scenario?Security Principles
- 85.A company is conducting a forensic investigation after a server was compromised. The investigators find that the attacker modified system logs to hide their activities and installed a backdoor that replaces legitimate system binaries with malicious versions. Which type of malware is the attacker most likely using to achieve these goals?Security Principles
- 86.A company is developing a new data classification policy. They decide to label data into categories such as 'Public,' 'Internal Use Only,' 'Confidential,' and 'Restricted.' What is the primary purpose of classifying data in this manner?Security Principles
- 87.A small non-profit organization is concerned about protecting donor information and financial records. They want to ensure that only authorized personnel can view this sensitive data. Which security principle are they primarily trying to uphold?Security Principles
- 88.A network administrator is configuring new firewall rules to restrict outbound traffic to only necessary services. This practice aligns with which fundamental security principle?Security Principles
- 89.A cybersecurity analyst is investigating a recent data breach. The preliminary findings indicate that the breach occurred through an unpatched vulnerability in an outdated content management system (CMS). The organization had a vulnerability management program in place, but this particular system was overlooked. Which aspect of the vulnerability management program MOST likely failed?Vulnerability Management
- 90.A large corporation is developing a new security awareness training program for its employees. One of the modules focuses on teaching employees to identify suspicious emails that attempt to trick them into revealing sensitive information, such as login credentials or financial data, by impersonating trusted entities. What type of attack is this module primarily aiming to combat?Security Principles
- 91.A cybersecurity analyst is investigating a report of a compromised web server. They discover that an attacker exploited a vulnerability in the server's operating system, gained root access, and installed a hidden program that allows persistent remote access while actively concealing its presence from common system utilities. What type of malware has most likely been installed?Security Principles
- 92.A security analyst is investigating a reported vulnerability in an internal web application. The vulnerability scanner flagged a potential 'SQL Injection' due to unsanitized input fields. However, after reviewing the application's source code, the development team confirms that all user inputs are rigorously validated and parameterized queries are used throughout the application. What is the MOST appropriate classification for this vulnerability report?Vulnerability Management
- 93.A new employee receives an email that appears to be from the CEO, urgently requesting their login credentials to resolve a critical system issue. The email contains a link to a fake login page that looks identical to the company's internal portal. This is a classic example of which common security threat?Security Principles
- 94.A security auditor is conducting a 'black-box' penetration test on a client's external web application. Which of the following statements accurately describes the primary characteristic of this type of assessment?Vulnerability Management
- 95.A small e-commerce company experiences a sudden and significant increase in network traffic to its web servers, causing the website to become unresponsive for legitimate customers. This traffic originates from thousands of unique IP addresses, overwhelming the server's resources. Which type of common security threat does this scenario most accurately describe?Security Principles
- 96.A large organization is implementing a new vulnerability management program. One of the key challenges is ensuring that all discovered vulnerabilities are tracked from identification through remediation and verification. Which component of a vulnerability management system is primarily responsible for maintaining the lifecycle status of vulnerabilities?Vulnerability Management
- 97.A cybersecurity team is setting up a honeypot to lure attackers and gather intelligence on their tactics, techniques, and procedures (TTPs). They want to make sure the honeypot appears as a legitimate, vulnerable system. Which of the following is the primary goal of deploying a honeypot in a network?Network Security
- 98.During the eradication phase of a malware incident, a security engineer discovers a sophisticated rootkit embedded deep within the operating system of several critical servers. Traditional antivirus and anti-malware tools have failed to remove it completely, and simply deleting files has proven ineffective due to persistence mechanisms. What is the MOST secure and reliable method to ensure complete eradication of this type of persistent threat?Incident Handling
- 99.A security analyst is investigating a sophisticated attack where an attacker managed to bypass perimeter defenses and establish a persistent foothold within the internal network. The attacker is using command-and-control (C2) communication disguised as normal HTTP traffic over port 80. Which advanced network security technology is specifically designed to detect and block such evasive, internal threats by analyzing traffic behavior and protocol anomalies?Network Security
- 100.A company is implementing a new security policy that requires all network traffic between different departments within the internal network to be encrypted and authenticated. This is to prevent any internal snooping or tampering. Which protocol suite is best suited for securing communications specifically at the network layer (Layer 3)?Network Security