Step2Study
IT & Technology200-301100% Free

Cisco Certified Support Technician (CCST) Cybersecurity

Practice bank
226 Qs
Real exam
40 Qs
Time limit
50 min
Passing
Variable, based on a combination of exam difficulty and statistical analysis.

Exam blueprint

Security Principles
20%
Network Security
20%
Endpoint Security
20%
Vulnerability Management
15%
Risk Management
15%
Incident Handling
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 113 min · pass 75% · 226 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Cisco Certified Support Technician (CCST) Cybersecurity practice test questions

Sample questions from the 226-question bank, with answers and explanations.

All questions
  1. 1. A security team is considering implementing a continuous vulnerability scanning solution. Which of the following is the PRIMARY benefit of continuous scanning compared to periodic, scheduled scans?

    Vulnerability Management

    • A. Earlier detection of newly introduced vulnerabilities.
    • B. Reduced false positives in scan reports.
    • C. Lower overall cost of vulnerability management.
    • D. More comprehensive coverage of all network assets.
    Show answer

    A. Earlier detection of newly introduced vulnerabilities.

    Continuous scanning provides near real-time visibility into the security posture, allowing for the much faster detection of new vulnerabilities introduced by changes in the environment, new software deployments, or newly discovered CVEs. While it might contribute to comprehensive coverage over time (D), its primary advantage over periodic scans is timeliness. It doesn't inherently reduce false positives (A) or guarantee lower cost (B), which depends on implementation.

  2. 2. A cybersecurity team is evaluating a software application for potential vulnerabilities. They discover that the application does not properly sanitize user input, allowing malicious scripts to be injected and executed in a user's web browser when viewing affected content. Which type of vulnerability does this scenario describe?

    Security Principles

    • A. Cross-Site Scripting (XSS)
    • B. Buffer Overflow
    • C. Denial of Service (DoS)
    • D. SQL Injection
    Show answer

    A. Cross-Site Scripting (XSS)

    The scenario describes an attacker injecting malicious client-side scripts into web pages viewed by other users due to improper input sanitization. This is the definition of a Cross-Site Scripting (XSS) vulnerability.

  3. 3. A security analyst is reviewing a vulnerability scan report. One identified vulnerability is a 'Missing Security Header' on a web server, which has a CVSS Base Score of 4.3 (Medium). The analyst determines that exploiting this vulnerability directly would require an attacker to chain it with other, more complex client-side vulnerabilities. Given this context, how might the 'Exploit Code Maturity' (E) CVSS Temporal metric be affected?

    Vulnerability Management

    • A. It would likely be rated 'High' due to the potential for chaining.
    • B. It would remain 'Not Defined' as it's a configuration issue.
    • C. It would likely be rated 'Unproven' or 'Proof-of-Concept' due to the dependency on complex chaining.
    • D. It would be rated 'Functional' because a header is clearly missing.
    Show answer

    C. It would likely be rated 'Unproven' or 'Proof-of-Concept' due to the dependency on complex chaining.

    Exploit Code Maturity (E) reflects the current state of exploit techniques or code availability. If exploiting a vulnerability requires complex chaining with other client-side issues, it implies that readily available, fully functional exploit code is unlikely to exist. Therefore, the maturity would likely be 'Unproven' or 'Proof-of-Concept' rather than 'Functional' or 'High'.

  4. 4. A cybersecurity analyst is evaluating a recently discovered vulnerability in a critical enterprise application. The vulnerability allows an unauthenticated attacker to bypass authentication mechanisms and gain administrative access. The application is publicly accessible and processes sensitive customer data. According to CVSS, which metric would primarily contribute to a 'High' score for the 'Confidentiality' impact?

    Vulnerability Management

    • A. Availability Impact
    • B. Attack Complexity
    • C. Integrity Impact
    • D. Confidentiality Impact
    Show answer

    D. Confidentiality Impact

    The scenario explicitly states that an unauthenticated attacker can gain administrative access to an application processing sensitive customer data. This directly impacts the confidentiality of that data, as unauthorized disclosure is possible.

  5. 5. A cybersecurity team is performing a comprehensive vulnerability assessment of a new cloud-native application. They want to identify security flaws that might only become apparent when the application is actively running and interacting with its environment. Which testing method is best suited for this purpose?

    Vulnerability Management

    • A. Dynamic Application Security Testing (DAST)
    • B. Manual Code Review
    • C. Static Application Security Testing (SAST)
    • D. Software Composition Analysis (SCA)
    Show answer

    A. Dynamic Application Security Testing (DAST)

    Dynamic Application Security Testing (DAST) analyzes a running application from the outside, simulating attacks to find vulnerabilities that are only detectable during execution, such as misconfigurations, runtime errors, or issues with authentication and session management. This directly addresses the need to find flaws 'when the application is actively running'.

  6. 6. A security team is conducting a vulnerability assessment on a new custom-developed application. They have access to the application's source code and are using static application security testing (SAST) tools to identify potential vulnerabilities before deployment. What is the primary advantage of using SAST in this phase of the software development lifecycle?

    Vulnerability Management

    • A. It helps detect vulnerabilities early in the development cycle, reducing remediation costs.
    • B. It provides a comprehensive view of network and infrastructure vulnerabilities.
    • C. It accurately simulates real-world attacks from an external perspective.
    • D. It can identify vulnerabilities that only appear during runtime.
    Show answer

    A. It helps detect vulnerabilities early in the development cycle, reducing remediation costs.

    The primary advantage of SAST is its ability to analyze source code (or compiled binaries) early in the development lifecycle, allowing developers to identify and fix vulnerabilities before the application is even deployed. This 'shift-left' approach significantly reduces the cost and effort of remediation compared to finding issues in production.

  7. 7. A security analyst is conducting a vulnerability assessment of a critical database server. They are provided with administrator credentials for the server to perform a more thorough scan. What type of vulnerability scan is the analyst performing?

    Vulnerability Management

    • A. Credentialed scan
    • B. External scan
    • C. Uncredentialed scan
    • D. Black-box scan
    Show answer

    A. Credentialed scan

    A credentialed scan involves providing the vulnerability scanner with legitimate authentication credentials (like administrator access) to the target system. This allows the scanner to access internal configurations, patch levels, and software versions, leading to a much more accurate and comprehensive assessment.

  8. 8. An organization is developing its cybersecurity incident response plan. A key component of the plan involves defining clear roles and responsibilities for the incident response team and establishing communication channels for reporting and escalating incidents. Which security program element is this organization primarily focusing on?

    Security Principles

    • A. Incident Response
    • B. Security Policy
    • C. Risk Assessment
    • D. Security Auditing
    Show answer

    A. Incident Response

    The scenario directly describes the development of an incident response plan, focusing on team roles, responsibilities, and communication channels for handling security incidents. This is the core of an Incident Response program.

  9. 9. A company is implementing a new digital signature system for all internal documents to ensure that the sender of a document cannot later deny having sent it. Which security principle is being primarily addressed by this implementation?

    Security Principles

    • A. Non-repudiation
    • B. Confidentiality
    • C. Integrity
    • D. Availability
    Show answer

    A. Non-repudiation

    Non-repudiation ensures that a party cannot successfully deny the validity of a message or action. Digital signatures provide proof of origin, directly addressing the goal of preventing a sender from denying their action.

  10. 10. A cybersecurity team is performing a vulnerability assessment on a new custom-developed web application. They want to identify security flaws in the application's code by analyzing it without actually executing the code. Which type of testing tool should they primarily use?

    Vulnerability Management

    • A. Interactive Application Security Testing (IAST)
    • B. Penetration Testing
    • C. Static Application Security Testing (SAST)
    • D. Dynamic Application Security Testing (DAST)
    Show answer

    C. Static Application Security Testing (SAST)

    Static Application Security Testing (SAST) tools analyze source code or compiled code without executing the application to find vulnerabilities, which aligns with the team's goal.

  11. 11. A cybersecurity analyst detects unusual outgoing network traffic from several workstations, indicating communication with known command-and-control (C2) servers. Further investigation reveals that these workstations have been infected with malicious software that is collecting data and awaiting further instructions. This scenario most clearly indicates an infection by which type of common security threat?

    Security Principles

    • A. Phishing
    • B. Botnet
    • C. Ransomware
    • D. Spyware
    Show answer

    B. Botnet

    The key indicators are 'infected with malicious software', 'collecting data', and 'awaiting further instructions' from 'command-and-control (C2) servers'. This describes a botnet, where compromised machines (bots) are controlled remotely by an attacker (bot-herder) to perform coordinated malicious activities.

  12. 12. A small business owner is implementing basic cybersecurity measures. They are particularly concerned about unauthorized access to their customer database, which contains sensitive personal information. They want to ensure that only authenticated and authorized employees can view or modify this data. Which security principle is primarily addressed by implementing strong access controls and authentication mechanisms?

    Security Principles

    • A. Confidentiality
    • B. Integrity
    • C. Non-repudiation
    • D. Availability
    Show answer

    A. Confidentiality

    Confidentiality ensures that information is accessible only to those authorized to have access. Implementing strong access controls directly supports this principle by preventing unauthorized disclosure.

  13. 13. A small e-commerce business experiences a sudden and massive influx of traffic to its website from thousands of compromised computers worldwide. This traffic overwhelms their servers, making the website inaccessible to legitimate customers. The attackers are demanding payment to stop the attack. This is an example of which type of common security threat?

    Security Principles

    • A. SQL Injection
    • B. Cross-Site Scripting (XSS)
    • C. Man-in-the-Middle (MitM)
    • D. Distributed Denial of Service (DDoS)
    Show answer

    D. Distributed Denial of Service (DDoS)

    The scenario describes a 'massive influx of traffic' from 'thousands of compromised computers worldwide' overwhelming servers and making the website 'inaccessible'. This perfectly matches the definition of a Distributed Denial of Service (DDoS) attack, where multiple sources coordinate to flood a target.

  14. 14. A security team is implementing a new vulnerability management program. They want to ensure that all assets within their network are regularly scanned for security weaknesses. However, they are concerned about the potential performance impact of scanning during peak business hours. Which factor is MOST critical to consider when scheduling vulnerability scans to balance thoroughness and operational continuity?

    Vulnerability Management

    • A. The frequency of new vulnerability disclosures for similar systems.
    • B. The operational impact window (maintenance windows) of the target systems.
    • C. The CVSS Base Score of the highest-rated vulnerability.
    • D. The number of vulnerabilities identified in previous scans.
    Show answer

    B. The operational impact window (maintenance windows) of the target systems.

    The operational impact window, often referred to as a maintenance window or off-peak hours, is crucial for scheduling scans. It ensures that thorough scanning can occur without disrupting critical business operations, directly addressing the concern about 'potential performance impact' and 'operational continuity'.

  15. 15. A security team is implementing a vulnerability management program and needs to establish a clear policy for handling vulnerabilities. Which of the following is the MOST critical first step in defining a comprehensive vulnerability management policy?

    Vulnerability Management

    • A. Conducting an initial vulnerability scan.
    • B. Selecting a vulnerability scanning tool.
    • C. Establishing a patching schedule for all systems.
    • D. Defining roles and responsibilities for vulnerability management.
    Show answer

    D. Defining roles and responsibilities for vulnerability management.

    Before any tools are selected or actions are taken, a clear definition of who is responsible for what aspects of vulnerability management is crucial. This ensures accountability, prevents duplication of effort, and establishes a clear chain of command for identifying, assessing, and remediating vulnerabilities.

  16. 16. A security team is considering using a vulnerability scanner that requires network access to the target systems but does not need any authentication credentials for those systems. What limitation should the team be aware of regarding the depth of analysis provided by this type of scan?

    Vulnerability Management

    • A. It can identify vulnerabilities requiring authenticated access for exploitation.
    • B. It primarily identifies network-level vulnerabilities and open ports.
    • C. It provides a comprehensive view of internal system vulnerabilities.
    • D. It can accurately detect missing patches and misconfigurations.
    Show answer

    B. It primarily identifies network-level vulnerabilities and open ports.

    An uncredentialed scan operates without authentication, simulating an external attacker's view. While it can find many vulnerabilities, its primary limitation is an inability to inspect internal system configurations, patch levels, or file permissions. Thus, it mainly detects network-level issues and identifies open services/ports visible externally.

  17. 17. A hospital's IT department is reviewing its data backup strategy after a recent ransomware attack that encrypted patient records. They need to ensure that critical patient data can be restored quickly and efficiently to minimize disruption to patient care. Which security principle is primarily addressed by a robust and tested data backup and recovery plan?

    Security Principles

    • A. Non-repudiation
    • B. Confidentiality
    • C. Availability
    • D. Integrity
    Show answer

    C. Availability

    Availability ensures that systems and data are accessible and usable when needed. A robust data backup and recovery plan is crucial for restoring service and data after an incident, directly supporting availability.

  18. 18. During a security audit, it is discovered that several employees have administrative access to systems far beyond what is required for their job functions. For instance, a marketing specialist can modify server configurations, and a junior accountant can access the human resources database. Which fundamental security principle is being violated in this situation?

    Security Principles

    • A. Implicit Deny
    • B. Need to Know
    • C. Separation of Duties
    • D. Least Privilege
    Show answer

    D. Least Privilege

    The scenario describes users having more access than necessary to perform their job, which is a direct violation of the Principle of Least Privilege. This principle dictates that users should only be granted the minimum permissions required for their tasks.

  19. 19. A large enterprise uses a variety of operating systems and applications across its network. The security team needs to ensure that all systems are regularly updated with the latest security patches to address known vulnerabilities. What is the most effective approach to manage and deploy these patches across the diverse environment?

    Vulnerability Management

    • A. Relying solely on end-users to update their own systems.
    • B. Disabling automatic updates to avoid system instability.
    • C. Implementing a centralized patch management system.
    • D. Manual patching of each system individually.
    Show answer

    C. Implementing a centralized patch management system.

    A centralized patch management system automates the process of identifying, downloading, testing, and deploying patches across a large and diverse network. This significantly improves efficiency, consistency, and the overall security posture by ensuring timely application of updates.

  20. 20. A security auditor is reviewing an organization's incident response plan. The plan outlines specific steps for detecting, analyzing, containing, eradicating, recovering from, and post-incident activities after a security breach. This structured approach is a key component of which security program element?

    Security Principles

    • A. Risk Management
    • B. Vulnerability Management
    • C. Incident Response
    • D. Security Awareness Training
    Show answer

    C. Incident Response

    The scenario explicitly describes the phases of handling a security breach, from detection to recovery and follow-up. This entire process is the core definition of Incident Response, a critical element of any security program.

  21. 21. A cybersecurity team has just completed a vulnerability scan of their production environment and generated a report with hundreds of findings. Before proceeding with remediation, they need to determine which vulnerabilities pose the most significant risk to the organization. Which of the following factors is LEAST important when prioritizing these vulnerabilities?

    Vulnerability Management

    • A. Age of the vulnerability (how long it has been known).
    • B. Business impact of the affected asset.
    • C. Availability of a security patch or workaround.
    • D. Exploitability of the vulnerability.
    Show answer

    A. Age of the vulnerability (how long it has been known).

    While the age of a vulnerability might correlate with exploit maturity, it's not a direct measure of current risk. Factors like exploitability, business impact, and the ease of remediation (patch availability) are far more critical for immediate prioritization. A very old, but unexploitable vulnerability on a non-critical asset is less urgent than a new, highly exploitable one on a critical system.

  22. 22. A network administrator observes unusual outbound connections from several internal workstations to an external IP address known to be associated with command-and-control (C2) servers. These connections are occurring even when users are not actively browsing. Which type of malware is most likely responsible for this behavior?

    Security Principles

    • A. Adware
    • B. Rootkit
    • C. Ransomware
    • D. Botnet
    Show answer

    D. Botnet

    Outbound connections to C2 servers indicate that the compromised machines are part of a botnet, awaiting instructions from a central command. This behavior is characteristic of bots being controlled remotely.

  23. 23. A security architect is designing a new network segment for highly sensitive financial data. They propose implementing a firewall at the perimeter, intrusion detection systems (IDS) within the segment, and host-based firewalls on individual servers, alongside strong access controls and encryption. Which overarching security strategy is being applied here?

    Security Principles

    • A. Defense in Depth
    • B. Security by Obscurity
    • C. Zero Trust Architecture
    • D. Principle of Least Privilege
    Show answer

    A. Defense in Depth

    The architect is proposing multiple layers of security controls (firewall, IDS, host-based firewalls, access controls, encryption) to protect the sensitive data. This layered approach is the definition of Defense in Depth.

  24. 24. A security team is implementing a new vulnerability management program. They decide to schedule weekly automated scans of their entire network infrastructure. What is the primary benefit of performing these scans with high frequency?

    Vulnerability Management

    • A. Lower operational costs for the security team.
    • B. Reduced false positives in scan reports.
    • C. Faster detection of newly introduced vulnerabilities.
    • D. Improved accuracy of vulnerability remediation.
    Show answer

    C. Faster detection of newly introduced vulnerabilities.

    Frequent vulnerability scans allow organizations to quickly identify and address new vulnerabilities that emerge due to new deployments, configuration changes, or newly discovered exploits, thereby reducing the window of exposure.

  25. 25. A company policy mandates that all critical vulnerabilities must be remediated within 7 days of discovery. A recent vulnerability scan identified a critical vulnerability (CVSS 9.0) in a legacy application that the vendor no longer supports, meaning no official patch is available. What is the MOST appropriate immediate action for the security team to take?

    Vulnerability Management

    • A. Disable the legacy application immediately.
    • B. Document the risk acceptance for the unsupported application.
    • C. Implement a compensating control, such as network segmentation or an IPS rule.
    • D. Develop a custom patch for the legacy application.
    Show answer

    C. Implement a compensating control, such as network segmentation or an IPS rule.

    Simply documenting risk acceptance (A) without any mitigation is inappropriate for a critical vulnerability, especially when policy mandates remediation. Developing a custom patch (C) is often complex, costly, and beyond the immediate capabilities of most security teams, and may introduce new vulnerabilities. Disabling the application (D) might be an option if it's not critical, but the question implies it's a 'legacy application' that is still in use. Implementing a compensating control (B) like network segmentation or an Intrusion Prevention System (IPS) rule is the most practical and immediate way to reduce the risk associated with an unpatchable critical vulnerability, buying time and reducing exposure.

Cisco Certified Support Technician (CCST) Cybersecurity flashcards

Tap a card to flip it. 150 flashcards in the full deck.

  • Continuous Vulnerability Scanning

    Flip card

    An automated process of regularly and frequently scanning an organization's IT assets for security vulnerabilities, often integrated into CI/CD pipelines and operational workflows.

    • Provides near real-time security posture visibility.
    • Reduces the window of exposure to new vulnerabilities.
    • Supports 'shift-left' security by integrating into development stages.
    Study this card →
  • Cross-Site Scripting (XSS)

    Flip card

    A type of security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to bypass access controls, impersonate users, or steal session cookies.

    • Involves injecting malicious JavaScript or HTML.
    • Executes in the victim's browser, not the server.
    • Often results from improper input validation/sanitization.
    Study this card →
  • CVSS Exploit Code Maturity (E)

    Flip card

    The CVSS Exploit Code Maturity (E) temporal metric measures the current state of exploit techniques or code availability for a vulnerability.

    • Rated as Not Defined, Unproven, Proof-of-Concept, Functional, or High.
    • Unproven means no exploit code is available or it's theoretical.
    • Functional means reliable exploit code is available, but may require some customization.
    Study this card →
  • CVSS Confidentiality Impact

    Flip card

    The CVSS Confidentiality Impact metric measures the impact on the confidentiality of the information managed by the vulnerable system if the vulnerability is exploited.

    • Rated as None, Low, or High.
    • High means there is a total loss of confidentiality, resulting in all resources within the impacted scope being divulged.
    • Low means there is some loss of confidentiality, but information disclosure is limited.
    Study this card →
  • Dynamic Application Security Testing (DAST)

    Flip card

    A black-box testing methodology that analyzes a running application from the outside to identify vulnerabilities by simulating attacks and observing application behavior.

    • Detects runtime vulnerabilities (e.g., authentication, session management, misconfigurations).
    • Does not require access to source code.
    • Identifies issues that only appear during execution.
    Study this card →
  • Static Application Security Testing (SAST)

    Flip card

    A 'white-box' testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the program.

    • Performed early in the SDLC (Shift Left).
    • Identifies vulnerabilities in source code.
    • Helps reduce remediation costs significantly.
    Study this card →
  • Credentialed Scan

    Flip card

    A vulnerability scan performed with valid authentication credentials to the target system, allowing for deeper inspection of internal configurations and patch levels.

    • Provides a more accurate and comprehensive vulnerability assessment.
    • Detects missing patches, misconfigurations, and software vulnerabilities.
    • Requires legitimate user accounts on target systems.
    Study this card →
  • Incident Response

    Flip card

    The organized approach an organization takes to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage and reduces recovery time and costs.

    • Follows a structured lifecycle (e.g., NIST SP 800-61).
    • Involves preparation, detection & analysis, containment, eradication & recovery, post-incident activity.
    • Requires clear roles, communication, and documentation.
    Study this card →
  • Non-repudiation

    Flip card

    The assurance that someone cannot deny something. In cybersecurity, it ensures that the sender cannot deny having sent a message, and the recipient cannot deny having received it.

    • Often implemented using digital signatures.
    • Provides proof of origin and integrity.
    • Crucial for legal and contractual agreements.
    Study this card →
  • Botnet

    Flip card

    A network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command-and-control (C2) server.

    • Used for coordinated attacks (DoS, spam, data theft).
    • Infected machines 'phone home' to C2 servers.
    • Users are often unaware their machine is part of a botnet.
    Study this card →
  • Confidentiality

    Flip card

    The security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.

    • Prevents unauthorized disclosure.
    • Achieved through encryption, access controls, and authentication.
    • Part of the CIA triad.
    Study this card →
  • Distributed Denial of Service (DDoS)

    Flip card

    A cyberattack where multiple compromised computer systems (a botnet) are used to flood a target system with traffic, rendering it unavailable to legitimate users.

    • Uses multiple sources to launch the attack.
    • Aims to exhaust resources (bandwidth, CPU, memory).
    • Makes services unavailable (denial of service).
    Study this card →
  • Vulnerability Scan Scheduling

    Flip card

    Vulnerability scan scheduling involves planning when to conduct scans to maximize their effectiveness in identifying vulnerabilities while minimizing impact on business operations.

    • Often performed during off-peak hours or dedicated maintenance windows.
    • Considerations include system criticality, network bandwidth, and potential for disruption.
    • Regularity is key for continuous monitoring, but timing is crucial for operational continuity.
    Study this card →
  • Vulnerability Management Policy

    Flip card

    A formal document outlining an organization's approach to identifying, assessing, prioritizing, and remediating security vulnerabilities.

    • Provides a framework for consistent vulnerability handling.
    • Includes roles, responsibilities, and procedures.
    • Essential for a mature cybersecurity posture.
    Study this card →
  • Uncredentialed Scan Limitations

    Flip card

    Drawbacks of performing a vulnerability scan without providing authentication credentials to the target system.

    • Limited to network-level services and open ports.
    • Cannot inspect internal configurations, patch levels, or file permissions.
    • May miss many internal vulnerabilities, leading to an incomplete risk picture.
    Study this card →
  • Availability

    Flip card

    The security principle that ensures authorized users have timely and uninterrupted access to information and resources when needed.

    • Ensures uptime and access.
    • Achieved through redundancy, backups, disaster recovery, and fault tolerance.
    • Part of the CIA triad.
    Study this card →
  • Principle of Least Privilege

    Flip card

    A security concept that dictates that a user, program, or process should be given only the minimum necessary rights, privileges, or permissions to perform its job or function, and no more. This limits the potential damage from a compromise.

    • Reduces the attack surface and potential impact of a breach.
    • Applies to users, applications, and services.
    • Often implemented through Role-Based Access Control (RBAC).
    Study this card →
  • Centralized Patch Management

    Flip card

    A system or process that automates the identification, testing, approval, and deployment of software updates and security patches across an organization's entire IT infrastructure.

    • Ensures consistent and timely application of patches.
    • Reduces manual effort and human error.
    • Improves overall security posture by closing known vulnerability gaps.
    Study this card →
  • Vulnerability Prioritization Factors

    Flip card

    Key elements considered when ranking vulnerabilities to determine which should be addressed first based on risk.

    • Exploitability: How easily can the vulnerability be exploited?
    • Impact: What is the potential damage if exploited?
    • Asset Criticality: How important is the affected system to the business?
    Study this card →
  • Defense in Depth

    Flip card

    A cybersecurity strategy that employs multiple layers of security controls to protect information and systems. The idea is that if one layer of defense is breached, another layer will be in place to prevent or detect further unauthorized access.

    • Based on military strategy of layered fortifications.
    • Combines administrative, technical, and physical controls.
    • Aims to slow down attackers and provide multiple detection points.
    Study this card →
  • Vulnerability Scan Frequency

    Flip card

    The rate at which vulnerability scans are performed on systems or networks.

    • Higher frequency reduces time-to-detection for new vulnerabilities.
    • Balances security needs with resource consumption.
    • Should be tailored to asset criticality and change rate.
    Study this card →
  • Mitigation for Unpatchable Vulnerabilities

    Flip card

    Strategies employed to reduce the risk of vulnerabilities for which no direct software patch or fix is available, often involving compensating controls or changes in environment.

    • Essential for unsupported or end-of-life software.
    • Focuses on reducing exploitability or impact.
    • Examples include network segmentation, access control, or IPS rules.
    Study this card →
  • Confidentiality (CIA Triad)

    Flip card

    The principle that sensitive information is protected from unauthorized access or disclosure. It ensures that data is only accessible to those who are authorized to view it.

    • Achieved through encryption, access controls, and proper data handling.
    • Prevents data breaches and unauthorized sharing.
    • A fundamental pillar of information security.
    Study this card →
  • Security Awareness Program

    Flip card

    A structured initiative designed to educate employees about cybersecurity threats, best practices, and their role in protecting organizational assets.

    • Reduces human error as a security vulnerability.
    • Should be continuous, relevant, and engaging.
    • Covers topics like phishing, password hygiene, data handling.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.