Cisco Certified Support Technician (CCST) Cybersecurity practice questions

226 free questions with answers and explanations.

Practice test
  1. 201.A company is concerned about employees downloading and executing unknown or potentially malicious files from the internet. They want to provide a safe environment for users to open suspicious attachments or browse untrusted websites without risking the integrity of their corporate workstations. Which endpoint security technology would best meet this requirement?Endpoint Security
  2. 202.A company is concerned about employees installing unapproved software on their work laptops, potentially introducing vulnerabilities or licensing issues. They want to implement a solution that limits what applications can be executed. Which endpoint security concept addresses this concern?Endpoint Security
  3. 203.A security auditor is checking an organization's workstations and discovers that several critical security settings, such as password complexity and automatic screen locking, are inconsistent across different departments. The organization wants to ensure a uniform and hardened security posture for all endpoints. Which endpoint security concept should they implement to address this inconsistency?Endpoint Security
  4. 204.A security team is regularly analyzing logs from endpoints to identify unusual patterns, unauthorized access attempts, or potential compromises. They are particularly interested in correlating events across multiple systems to detect a coordinated attack. Which endpoint security concept does this activity best represent?Endpoint Security
  5. 205.An organization is concerned about phishing attacks and zero-day malware attempting to exploit vulnerabilities in web browsers or document readers on employee workstations. They want a solution that can isolate these high-risk applications from the rest of the operating system, limiting potential damage if an exploit is successful. Which security concept is being sought?Endpoint Security
  6. 206.A security engineer is designing an endpoint security strategy for a highly regulated financial institution. A critical requirement is to prevent sensitive customer data, such as credit card numbers and social security numbers, from being copied to USB drives, sent via unencrypted email, or uploaded to unauthorized cloud storage services from any corporate endpoint. Which endpoint security technology is specifically designed to enforce these data handling policies?Endpoint Security
  7. 207.A remote employee reports that their company-issued laptop was stolen from their car. The company's primary concern is preventing unauthorized access to the sensitive data stored on the laptop's hard drive. Which endpoint security control is most crucial in mitigating this risk?Endpoint Security
  8. 208.A security administrator is implementing a system to prevent unauthorized devices from connecting to the corporate network, even if they have valid user credentials. This system should inspect device health and compliance before granting network access. Which endpoint security technology is being described?Endpoint Security
  9. 209.A security administrator is implementing a new policy to restrict unauthorized devices from connecting to the corporate network. The goal is to ensure that only compliant and approved endpoints can access network resources. Which endpoint security technology is best suited to achieve this objective?Endpoint Security
  10. 210.A security administrator is configuring a new web server. Following the principle of least functionality, which of the following actions should the administrator take?Endpoint Security
  11. 211.Which of the following endpoint security technologies primarily focuses on detecting and preventing malicious software from executing on a device?Endpoint Security
  12. 212.A company is implementing a new policy for all employee workstations that requires regular scans for misconfigurations, missing patches, and known security vulnerabilities. The goal is to proactively identify and address weaknesses before they can be exploited. Which endpoint security technology or process is being described?Endpoint Security
  13. 213.A security auditor discovers that several critical servers in a data center are running operating systems and applications with known vulnerabilities for which patches have been available for months. This oversight significantly increases the risk of exploitation. Which endpoint security best practice has been neglected in this scenario?Endpoint Security
  14. 214.A company is implementing a new BYOD (Bring Your Own Device) policy. To protect corporate data accessed on personal devices, they decide to use a solution that can remotely wipe corporate data without affecting personal data, and enforce specific security policies for corporate applications. Which technology is best suited for this requirement?Endpoint Security
  15. 215.A security team is deploying a new web application and needs to ensure the server hosting the application has a minimal attack surface. They decide to remove all unnecessary software, close all unneeded ports, and configure strong access controls. This approach is a direct application of which endpoint security concept?Endpoint Security
  16. 216.A large enterprise is struggling to maintain consistent security configurations across its thousands of endpoints, including desktops, laptops, and servers. New devices are often deployed with default settings, and existing devices frequently drift from the hardened baseline. Which endpoint security best practice, when properly implemented, would directly address these challenges by defining and enforcing a standardized, secure state for all endpoints?Endpoint Security
  17. 217.A software development company wants to ensure that all code developed internally is free from known vulnerabilities before it is deployed. They need a tool that can analyze the source code and identify security flaws early in the development lifecycle. Which type of tool would be most appropriate?Endpoint Security
  18. 218.A security analyst is investigating a suspected malware infection on an employee's workstation. The analyst observes unusual network activity originating from the device, including connections to unknown external IP addresses. Which of the following endpoint security technologies would be most effective in actively preventing this type of malicious outbound communication?Endpoint Security
  19. 219.A multinational corporation is deploying new laptops to its employees worldwide. Due to the high risk of theft or loss, especially for remote and traveling staff, the company policy dictates that all data on these devices must be rendered unreadable to anyone without proper authorization, even if the device is physically compromised. Which endpoint security technology ensures this data protection requirement?Endpoint Security
  20. 220.A company is implementing a new endpoint security strategy. They are particularly concerned about advanced persistent threats (APTs) that might bypass traditional antivirus solutions. Which technology offers continuous monitoring, detection, and automated response capabilities specifically tailored for endpoints?Endpoint Security
  21. 221.A security audit identifies that several critical servers and workstations in the engineering department are running outdated operating systems with known vulnerabilities. The IT department cites application compatibility issues as a reason for not upgrading. Which endpoint security best practice is being neglected, and what is its primary purpose?Endpoint Security
  22. 222.A security engineer is evaluating the effectiveness of the company's current endpoint security posture against zero-day exploits. They note that traditional signature-based antivirus frequently fails to detect these new threats. Which advanced detection technique would provide a better defense against polymorphic malware and unknown threats?Endpoint Security
  23. 223.A security analyst is investigating a compromised workstation that was recently isolated from the network. They discover that the attacker exploited a vulnerability in an unpatched operating system and then used a privilege escalation technique. Which of the following best describes the next immediate action the analyst should take to prevent further spread and re-infection?Endpoint Security
  24. 224.A security administrator is configuring a new server. To minimize its attack surface, they are ensuring that only essential services and applications are installed and running, and all unnecessary ports are closed. This practice aligns with which security principle?Endpoint Security
  25. 225.A cybersecurity analyst is investigating a persistent threat actor that is using a variety of sophisticated techniques to evade detection and maintain long-term access to a target network. The attacker's goal is to exfiltrate sensitive intellectual property over an extended period without being noticed. Which of the following terms best describes this type of threat?Network Security
  26. 226.A cybersecurity analyst is evaluating a critical web server that hosts the company's main e-commerce platform. They have identified a high-severity vulnerability that could lead to a complete compromise of customer data. The cost to implement a patch immediately is estimated at $5,000. However, if exploited, the estimated financial loss due to data breach fines, reputational damage, and recovery efforts is $2,000,000. The analyst recommends immediately patching the vulnerability. Which risk management strategy is the analyst primarily recommending?Risk Management