Cisco Certified Support Technician (CCST) Cybersecurity practice questions

226 free questions with answers and explanations.

Practice test
  1. 101.A network administrator is implementing a security measure to prevent unauthorized access to a company's internal network from the internet. Which of the following network security devices is primarily designed to filter traffic based on predefined rules and enforce security policies at the network perimeter?Network Security
  2. 102.A security analyst is investigating a sophisticated attack where an attacker managed to bypass perimeter defenses and establish a persistent foothold within the internal network. The attacker is using command-and-control (C2) communication disguised as normal HTTP traffic over port 80. Which advanced network security technology is specifically designed to detect and block such evasive, internal threats by analyzing traffic behavior and protocol anomalies?Network Security
  3. 103.During the eradication phase of a malware incident, a security engineer discovers a sophisticated rootkit embedded deep within the operating system of several critical servers. Traditional antivirus and anti-malware tools have failed to remove it completely, and simply deleting files has proven ineffective due to persistence mechanisms. What is the MOST secure and reliable method to ensure complete eradication of this type of persistent threat?Incident Handling
  4. 104.A cybersecurity team is setting up a honeypot to lure attackers and gather intelligence on their tactics, techniques, and procedures (TTPs). They want to make sure the honeypot appears as a legitimate, vulnerable system. Which of the following is the primary goal of deploying a honeypot in a network?Network Security
  5. 105.A company is implementing a new security policy that requires all network traffic between different departments within the internal network to be encrypted and authenticated. This is to prevent any internal snooping or tampering. Which protocol suite is best suited for securing communications specifically at the network layer (Layer 3)?Network Security
  6. 106.A small business is setting up its first network and wants to ensure that all internal network traffic is protected from eavesdropping by unauthorized devices, even if they gain access to the physical network. The business needs a solution that encrypts all data packets exchanged between devices on the local network. Which security technology should be implemented?Network Security
  7. 107.A security operations center (SOC) analyst receives an alert indicating a successful brute-force attack against a critical administrative portal. The immediate next step, according to standard incident response procedures, should focus on preventing further compromise while gathering initial information. Which of the following actions is the most appropriate next step?Incident Handling
  8. 108.A security analyst is investigating a suspected data breach where an attacker exfiltrated sensitive customer information. The post-incident analysis reveals that the attacker gained access through a web application vulnerability that allowed them to execute arbitrary commands on the underlying server. Which type of attack did the attacker most likely use to achieve this?Network Security
  9. 109.A security team is conducting a post-incident review after a significant data breach. They are analyzing the timeline of events, the effectiveness of their response actions, and identifying areas for improvement in their processes and technologies. Which of the following incident handling concepts is this activity primarily focused on?Incident Handling
  10. 110.A network administrator is configuring a new switch and wants to prevent unauthorized devices from connecting to specific switch ports. The administrator needs a solution that will only allow devices with known MAC addresses to connect, and if an unknown MAC address attempts to connect, the port should shut down. Which security feature should the administrator implement?Network Security
  11. 111.A cybersecurity analyst is investigating a persistent threat actor that is using a variety of sophisticated techniques to compromise network defenses, including zero-day exploits and custom malware. The actor maintains a long-term presence within the network to exfiltrate sensitive data. Which term best describes this type of threat?Network Security
  12. 112.A security engineer is analyzing a network where an attacker has successfully compromised an internal server and is now attempting to move laterally to other systems. The attacker is using Address Resolution Protocol (ARP) spoofing to redirect traffic from other internal hosts to their compromised server. Which network security measure can specifically detect and prevent such ARP-based attacks?Network Security
  13. 113.A cybersecurity incident response team is developing a new incident response plan. They are currently focusing on establishing clear communication channels, defining roles and responsibilities for team members, and ensuring all necessary tools and resources are in place before any incident occurs. Which incident handling concept are they primarily addressing?Incident Handling
  14. 114.A company experiences a data breach where sensitive customer information is exfiltrated. After containing and eradicating the threat, the incident response team begins restoring affected systems from backups and verifying that all services are functioning correctly and securely. Which phase of the incident response process are they currently executing?Incident Handling
  15. 115.A network security engineer is designing a secure network architecture for a critical industrial control system (ICS). Due to the highly sensitive nature of the system, all communication between the operational technology (OT) network and the enterprise IT network must be strictly controlled and unidirectional, allowing data to flow only from OT to IT, but never the other way. Which specialized security technology is specifically designed to enforce this type of unidirectional data flow?Network Security
  16. 116.A security analyst receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address on a non-standard port. The analyst confirms that this traffic is not part of any legitimate business process. Which phase of the incident response process should the analyst immediately focus on?Incident Handling
  17. 117.A company is upgrading its network infrastructure and wants to implement a solution that can identify and block malicious traffic before it reaches internal systems, based on known attack signatures and behavioral anomalies. The solution should also be able to inspect encrypted traffic. Which security technology best fits this description?Network Security
  18. 118.A small business is setting up its first network and is concerned about protecting against common network attacks. They want to implement a solution that can inspect network traffic at the application layer, enforce security policies based on application type, and provide stateful inspection capabilities. Which network security technology would best meet these requirements?Network Security
  19. 119.A security analyst is investigating a compromised web server. They suspect a zero-day exploit was used, and the attacker has established persistence. The analyst needs to apply a temporary patch or configuration change to prevent further exploitation while a permanent solution is developed. This action is best described as part of which containment strategy?Incident Handling
  20. 120.A security auditor is reviewing a company's network and finds that sensitive data is being transmitted in cleartext over an internal network segment, making it vulnerable to eavesdropping. The auditor recommends implementing a cryptographic solution to protect this data in transit. Which cryptographic goal is primarily addressed by encrypting the data?Network Security
  21. 121.A security auditor is reviewing a company's network configuration and identifies several servers that are directly accessible from the internet, but only need to serve web traffic (HTTP/HTTPS). To minimize the attack surface, the auditor recommends restricting inbound traffic to only the necessary ports. Which port numbers should be explicitly allowed for HTTP and HTTPS traffic?Network Security
  22. 122.A critical server in a pharmaceutical company's research and development department has been infected with ransomware. The incident response team has contained the infection and is now in the eradication phase. Which of the following actions would be the MOST appropriate next step?Incident Handling
  23. 123.A network security engineer is configuring a new network segment for highly sensitive financial data. The requirement is to ensure that only specific, known devices with pre-approved MAC addresses can connect to this segment. Any unknown device attempting to connect must be automatically blocked. Which switch feature should be configured to enforce this policy?Network Security
  24. 124.A company's email server is experiencing a Denial of Service (DoS) attack, causing widespread email outages. The incident response team has identified the source IP addresses of the attack. Which of the following incident response tools would be most effective in immediately mitigating this attack by blocking the malicious traffic?Incident Handling
  25. 125.During an incident, a security analyst needs to ensure that all evidence collected from a compromised system is preserved in an unalterable state for forensic analysis and potential legal proceedings. Which of the following incident response tools is specifically designed for this purpose?Incident Handling
  26. 126.During the containment phase of an incident, a security team discovers that a compromised server is still actively communicating with an external command-and-control (C2) server. To prevent further data exfiltration and control, they decide to block the C2 server's IP address at the perimeter firewall and isolate the compromised server from the network. What is the primary goal of these actions?Incident Handling
  27. 127.A network administrator is troubleshooting an issue where a user's computer, connected to a wired network, is receiving an IP address from an unauthorized DHCP server configured by an attacker. This is causing the user to route traffic through the attacker's device. Which network security feature can mitigate this attack by allowing only trusted DHCP servers to provide IP addresses?Network Security
  28. 128.A company is implementing a new security policy that dictates all network devices must have their configurations backed up regularly and stored in an encrypted format. Additionally, all access to these devices for configuration changes must be logged and audited. What overarching security principle is this policy primarily addressing?Network Security
  29. 129.A large enterprise is implementing a new security policy that mandates automated vulnerability scanning of all network devices and servers on a quarterly basis. The goal is to proactively identify security weaknesses and misconfigurations before they can be exploited. Which security technology is designed to perform this task?Network Security
  30. 130.A security analyst is investigating a phishing attack where an employee clicked a malicious link, potentially leading to malware infection. The analyst needs to determine if the link led to a download, what files were accessed, and if any data was exfiltrated. Which of the following incident response tools would provide the most relevant information for this initial investigation?Incident Handling
  31. 131.A security team is evaluating incident response capabilities and wants to implement a system that can automatically block known malicious IP addresses and domains at the network perimeter. Which of the following incident response tools would best fulfill this requirement?Incident Handling
  32. 132.A security analyst is investigating a suspected insider threat incident. The analyst has identified an employee who accessed highly sensitive financial records outside of their normal work hours and then attempted to delete system logs. The company policy dictates that such activity requires immediate isolation of the employee's network access and workstation. Which type of containment strategy is being applied?Incident Handling
  33. 133.A cybersecurity analyst is investigating a potential incident where an internal user's workstation is exhibiting unusual network traffic patterns, including frequent connections to a known malicious IP address and attempts to exfiltrate data to an external server. The analyst needs to isolate this workstation from the rest of the corporate network immediately without shutting it down, to prevent further compromise while preserving its state for forensic analysis. Which network security best practice should the analyst implement?Network Security
  34. 134.A security incident response team is analyzing a breach where an attacker exploited a vulnerability in a web application to gain unauthorized database access. The team determines that the vulnerability was due to improper input validation, allowing malicious SQL commands to be executed. Which type of attack occurred?Network Security
  35. 135.A security team is analyzing logs from a web server that was recently compromised. They need to identify the initial access vector, the commands executed by the attacker, and any files that were modified or exfiltrated. Which type of incident response tool would be most effective for this task?Incident Handling
  36. 136.A network administrator is designing a secure network for a hospital. The design requires that all medical devices communicate only with authorized servers and are completely isolated from the internet and the general administrative network. Which network security technology would best achieve this stringent isolation while ensuring necessary internal communication?Network Security
  37. 137.A network architect is designing a secure guest Wi-Fi network for a corporate office. The primary goal is to ensure that guest users have internet access but are completely isolated from the internal corporate network and cannot communicate with each other. Which combination of network security concepts should be implemented?Network Security
  38. 138.A security team is implementing a new policy that requires all network traffic between internal servers in different data center segments to be encrypted and authenticated. This ensures both confidentiality and integrity of data in transit within the private network. Which protocol is best suited for this requirement?Network Security
  39. 139.A network technician is troubleshooting a network connectivity issue where a new host cannot obtain an IP address from the DHCP server. Upon inspection, the technician discovers that the switch port to which the host is connected has been configured to only allow DHCP messages from trusted ports, and this specific port is not trusted. Which security feature is likely preventing the host from getting an IP address?Network Security
  40. 140.A security analyst is investigating a suspected data breach. During the investigation, it is discovered that an attacker compromised a server and created a new administrative user account. The attacker then used this new account to exfiltrate sensitive data. Which of the following security controls, if properly implemented and monitored, would have been most effective in detecting the creation of the unauthorized administrative account?Network Security
  41. 141.A cybersecurity analyst is investigating a network intrusion where an attacker gained unauthorized access to internal systems by exploiting a vulnerability in a web application. The attacker then used this access to pivot to other servers within the network. Which security concept, if properly implemented, would have best limited the attacker's ability to move laterally across the network after the initial compromise?Network Security
  42. 142.An organization is developing its incident response plan. A key consideration is defining the criteria for classifying incidents by severity and impact, which will guide resource allocation and communication protocols during an active event. Which incident handling concept is being addressed by defining these criteria?Incident Handling
  43. 143.A network security engineer is configuring a web server to ensure that all communication between clients and the server is encrypted and authenticated. The engineer specifically wants to prevent man-in-the-middle attacks and ensure the integrity of the data exchanged. Which protocol combination is most appropriate for achieving these goals for web traffic?Network Security
  44. 144.A small business owner is concerned about employees accidentally downloading malware from suspicious websites. They want to implement a solution that filters web content and prevents access to known malicious domains. Which network security technology is best suited for this purpose?Network Security
  45. 145.An incident response team is analyzing a recent breach where an attacker was able to gain access to a critical server by exploiting a zero-day vulnerability in its operating system. Before the breach, the server was protected by a traditional firewall and an antivirus solution. Which advanced security concept, if implemented, might have offered better protection against this unknown threat?Network Security
  46. 146.A critical server has been compromised, and the incident response team has identified the malware used. Before restoring the system, they must ensure the malware and its remnants are completely removed, and any backdoors created are closed. Which incident response phase does this activity belong to?Incident Handling
  47. 147.A company is implementing a security policy that requires all remote access to its internal network to use a secure, encrypted tunnel over the public internet. Which network technology is best suited to fulfill this requirement, providing both secure connectivity and data privacy?Network Security
  48. 148.A network security engineer is designing a secure network architecture for a critical infrastructure system. The design requires that network devices (routers, switches) and servers hosting critical applications are physically isolated from the general corporate network. This isolation prevents direct access from less trusted segments and limits the impact of a breach in the corporate network. Which network design concept is being applied here?Network Security
  49. 149.A security administrator is investigating a series of Denial-of-Service (DoS) attacks targeting the company's public-facing web servers. The attacks are characterized by a flood of legitimate-looking HTTP requests originating from a large number of compromised machines distributed globally. Which type of attack is being described, and what is the most effective mitigation strategy?Network Security
  50. 150.A network technician is configuring a new switch and needs to implement a security feature that prevents unauthorized devices from connecting to specific switch ports. This feature should allow only pre-approved MAC addresses to communicate through those ports. Which switch security feature should the technician configure?Network Security