Cisco Certified Support Technician (CCST) Cybersecurity — Free Practice Questions
10 free sample questions from a bank of 180, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following best describes the purpose of an information security assessment?
To identify and mitigate security vulnerabilities and risks
To create a comprehensive inventory of IT assets
To determine the level of compliance with industry standards and regulations
To assess the impact of changes on organizational processes
Answer: A
The short version
A — An assessment finds and helps fix weaknesses. Its purpose is to identify vulnerabilities and risks so they can be mitigated.
Key concepts in this question
Security assessment: systematic review of controls, vulnerabilities, and risk exposure.
Vulnerability versus asset list: finding weaknesses differs from merely counting assets.
Outcome: prioritized remediation, not just a compliance checkbox.
Why A is correct
An information security assessment examines systems, policies, and controls to uncover vulnerabilities and evaluate the risk they pose, then recommends mitigations. That identify-and-mitigate purpose is the core definition, making A the best description of why organizations perform assessments.
Why the others are wrong
B. Building an IT asset inventory is a supporting step, not the purpose of the assessment itself.
C. Compliance measurement may use assessment results, but assessments target risk reduction, not just regulatory alignment.
D. Assessing change impact on processes describes change management, not a security assessment.
100-160 exam tip
Assessment equals hunt weakness then fix: always pick identify and mitigate.
2Which approach to risk management involves accepting the potential risk and not taking any specific action to mitigate it?
Risk acceptance.
Risk mitigation.
Risk transfer.
Risk avoidance.
Answer: A
The short version
A — Risk acceptance means living with the risk. The organization consciously takes no further action.
Key concepts in this question
Risk acceptance: acknowledge the risk and continue operating without extra controls.
Mitigation: add controls to reduce likelihood or impact.
Transfer versus avoidance: shift the loss (insurance) or stop the risky activity entirely.
Why A is correct
Acceptance is the response where the potential loss is judged tolerable or costlier to fix than to bear, so management formally accepts it and applies no specific countermeasure. That matches the stem's accept-and-do-nothing wording exactly.
Why the others are wrong
B. Mitigation actively reduces risk with controls, the opposite of doing nothing.
C. Transfer shifts financial impact to a third party such as an insurer.
D. Avoidance eliminates the risk by discontinuing the activity that creates it.
3You need to diagram an intrusion event by using the Diamond Model.Move each event detail from the list on the left to the correct location in the diagram on the right.Note: You will receive partial credit for each correct response.
Answer:
The short version
Group is the adversary, mail server the infrastructure, phishing the capability, databases the victim. Diamond Model 101.
Key concepts in this question
Adversary: the threat actor — here the ransomware group behind the intrusion.
Infrastructure: attacker-controlled or abused systems used for delivery — the email server and domain name.
Capability: the tools and techniques — phishing email carrying malware.
Victim: the target asset — the customer and product databases.
Why this mapping is correct
The Diamond Model places the actor at the adversary vertex, so the ransomware group maps there. The email server and domain are the infrastructure abused to reach the target. The phishing email with malware is the capability employed. The databases suffering the intrusion are the victim at the bottom vertex.
Why the others are wrong
Databases as infrastructure mistakes the target asset for attacker tooling.
Group as capability confuses who attacks with what they use.
Phishing as victim puts the weapon where the target belongs.
Server as adversary personifies abused infrastructure as the actor.
100-160 exam tip
Who, with what, over what, against what — adversary, capability, infrastructure, victim.
4Which of the following ensures that a computer system has the latest security fixes and improvements?
Windows Update
Device drivers
Application updates
Firmware updates
Answer: A
The short version
A — Windows Update delivers the latest OS security fixes. It patches the operating system itself against known flaws.
Key concepts in this question
OS patching: closes vulnerabilities in Windows components attackers exploit.
Windows Update: Microsoft's channel for security and quality updates.
Scope: OS updates versus driver, application, or firmware-only updates.
Why A is correct
Keeping a system current against security flaws means applying operating-system patches, and on Windows that channel is Windows Update. It delivers the monthly security rollups and out-of-band fixes that harden the core OS, which is what the stem asks for.
Why the others are wrong
B. Device drivers enable hardware; updating them fixes compatibility, not OS-wide security.
C. Application updates patch individual programs, not the underlying system.
D. Firmware updates patch hardware-level code, a narrower scope than full OS security fixes.
100-160 exam tip
System-wide fixes means the OS updater: on Windows that is always Windows Update.
5Which of the following is the most secure and recommended method for storing sensitive user data in a database?
Storing the data in plain text
Using symmetric encryption
Using hashing algorithms
Using asymmetric encryption
Answer: C
The short version
C — Store sensitive data as hashes, not recoverable text. One-way hashing with salt protects passwords even if the database leaks.
Key concepts in this question
Hashing: one-way function; the original value cannot be decrypted back.
Salting: unique random data per record defeats rainbow-table attacks.
Encryption versus hashing: encrypted data is reversible with a key, hashes are not.
Why C is correct
Best practice for passwords and similar secrets is salted hashing: the system stores only the digest and verifies logins by re-hashing the attempt. A stolen database then yields no usable credentials, whereas any reversible storage would expose them once keys leak.
Why the others are wrong
A. Plain text is the worst option; any breach immediately exposes every secret.
B. Symmetric encryption is reversible, so a stolen key decrypts all records.
D. Asymmetric encryption is also reversible with the private key and is impractical for bulk credential storage.
100-160 exam tip
Passwords are hashed, data in transit is encrypted: never store logins reversibly.
6Which of the following best describes the concept of defense in depth in cybersecurity?
Utilizing multiple layers of security controls to protect against different types of threats
Running regular vulnerability scans to maintain the integrity of the system
Implementing access controls to ensure availability of critical resources
Encrypting sensitive data to maintain confidentiality
Answer: A
The short version
A — Defense in depth stacks multiple layers of controls. If one layer fails, the next still blocks the threat.
Key concepts in this question
Layered controls: firewall, IDS/IPS, endpoint, identity, and encryption working together.
Breadth: covers different attack vectors rather than one threat type.
Redundancy: no single point of defensive failure.
Why A is correct
Defense in depth is the strategy of deploying overlapping administrative, technical, and physical controls so diverse threats are caught at different stages. The stem's multiple-layers-against-different-threats phrasing is the textbook definition.
Why the others are wrong
B. Vulnerability scanning is one useful control, not the layered strategy itself.
C. Access controls protect availability and authorization but are a single layer.
D. Encryption protects confidentiality but is likewise only one layer.
100-160 exam tip
Depth means layers: any answer with multiple overlapping controls is defense in depth.
7Which of the following best describes an Advanced Persistent Threat (APT)?
An unintentional and harmless interaction with a computer system
A security incident caused by human error or negligence
A targeted cyber attack that aims to gain unauthorized access to sensitive information
A type of malware designed to disrupt computer networks
Answer: C
The short version
C — An APT is a targeted, persistent intrusion for sensitive data. Skilled actors stay hidden long-term to steal information.
Key concepts in this question
Targeted: aimed at a specific organization or data set, not opportunistic.
Persistent: long dwell time with stealthy footholds and lateral movement.
Objective: espionage or data theft rather than immediate disruption.
Why C is correct
Advanced Persistent Threats combine advanced capability with a sustained campaign: attackers gain unauthorized access, evade detection, and quietly exfiltrate sensitive information over months. The targeted-access-to-sensitive-information wording captures all three APT traits.
Why the others are wrong
A. APTs are deliberate and harmful, never harmless accidents.
B. Human error describes insider mistakes, not a sophisticated external campaign.
D. Disruptive malware describes worms or wipers; APTs prioritize stealthy theft over breakage.
100-160 exam tip
APT equals patient thief: targeted, quiet, and after your data for the long haul.
8Which of the following tools is primarily used for analyzing network packets?
Cisco AnyConnect
Wireshark
Oracle Database
Norton Antivirus
Answer: B
The short version
B — Wireshark is the packet analyzer. It captures frames and decodes every protocol layer.
Key concepts in this question
Packet analysis: capturing traffic and inspecting headers and payloads.
Wireshark: free protocol analyzer with capture filters, display filters, and dissectors.
Tool roles: analyzer versus VPN client, database, or antivirus.
Why B is correct
Wireshark's sole purpose is intercepting network packets and dissecting them protocol by protocol, which is exactly the job in the stem. Analysts use it to troubleshoot, verify attacks, and examine malicious traffic in SOC workflows.
Why the others are wrong
A. Cisco AnyConnect is a VPN and endpoint-security client, not an analyzer.
C. Oracle Database is a relational database platform with no packet-capture role.
D. Norton Antivirus detects and removes malware on hosts; it does not decode packets.
100-160 exam tip
Shark eats packets: see analyze traffic and answer Wireshark.
9Which of the following refers to a list of all hardware components installed on an endpoint system?
Configuration inventory
Hardware inventory
Software inventory
Firmware inventory
Answer: B
The short version
B — Installed hardware is tracked in the hardware inventory. It lists every physical component in the endpoint.
Key concepts in this question
Hardware inventory: CPUs, memory, disks, NICs, and peripherals per device.
Configuration inventory: broader settings and baselines, not just parts.
Software versus firmware: installed programs and embedded code, tracked separately.
Why B is correct
Asset programs distinguish what the machine is made of from what runs on it. A list of all installed physical components is by definition the hardware inventory, used for lifecycle planning, support, and vulnerability scoping.
Why the others are wrong
A. Configuration inventory covers settings and compliance state, not the parts list itself.
C. Software inventory lists installed applications and OS packages, not hardware.
D. Firmware inventory tracks BIOS and embedded versions, only a slice of the hardware.
100-160 exam tip
Match the noun: hardware parts live in the hardware inventory.
10Which of the following is a common proactive measure for managing vulnerabilities?
Regularly updating antivirus signatures
Performing regular system backups
Implementing data encryption
Conducting vulnerability assessments
Answer: D
The short version
D — Vulnerability assessments proactively hunt weaknesses. Regular scans find flaws before attackers exploit them.
Key concepts in this question
Proactive: seeking weaknesses ahead of incidents rather than reacting afterward.
Vulnerability assessment: scheduled scans plus prioritized remediation.
Hygiene versus recovery: finding flaws differs from backups or encryption.
Why D is correct
Conducting vulnerability assessments is inherently proactive: scanners inventory systems, test for known CVEs and misconfigurations, and report what to fix. Repeating them on schedule is the standard proactive measure in vulnerability-management programs.
Why the others are wrong
A. Updating antivirus signatures improves detection but reacts to known malware, not system flaws.
B. Backups enable recovery after damage; they do not find or prevent vulnerabilities.
C. Encryption protects data confidentiality but does not discover weaknesses.
100-160 exam tip
Proactive plus vulnerabilities always points to scheduled assessments and scans.