10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free CCST-C questions are organized by exam domain, so you can see how each part of the Cisco Certified Support Technician - Cybersecurity blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Essential Security Principles - Define essential security principles including vulnerabilities, threats, exploits, risks, attack vectors, hardening, defense-in-depth, confidentiality, integrity, availability (CIA), types of attackers, reasons for attacks and code of ethics; explain common threats and vulnerabilities including malware, ransomware, denial of service, botnets, social engineering attacks such as tailgating, spear phishing, phishing, vishing and smishing, physical attacks, man in the middle, IoT vulnerabilities, insider threats and Advanced Persistent Threats (APT); explain access management principles including authentication, authorization and accounting (AAA), RADIUS, multifactor authentication (MFA) and password policies; explain encryption methods and applications including encryption types, hashing, certificates, public key infrastructure (PKI), strong versus weak encryption algorithms, data in transit, data at rest, data in use and protocols using encryption.
Question 1
A security technician receives an email appearing to be from a finance director requesting an urgent wire transfer. The sender address is slightly different from the real domain and pressure is used to force immediate action. Which attack technique is demonstrated?
Show answer & explanation
Correct answer: B - Spear phishing
Question 2
A company requires employees to verify identity with a password and fingerprint before accessing sensitive systems. Which security principle is strengthened?
Show answer & explanation
Correct answer: A - Multifactor authentication
Domain 2: Basic Network Security Concepts - Describe TCP/IP protocol vulnerabilities including TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS; explain how network addresses impact network security including IPv4 and IPv6 addresses, MAC addresses, network segmentation, CIDR notation, NAT and public versus private networks; describe network infrastructure and technologies including network security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS and IPS; set up a secure wireless SoHo network including MAC address filtering, encryption standards and protocols and SSID; implement secure access technologies including ACL, firewall, VPN and NAC.
Question 3
A network administrator places a public-facing web server in a separate zone between the internet and internal network. What component is being used?
Show answer & explanation
Correct answer: B - DMZ
Question 4
A technician observes a device responding to traffic intended for another device by using forged address information. Which weakness is involved?
Show answer & explanation
Correct answer: A - ARP spoofing
Question 5
A small office administrator configures wireless security. Which approach provides the strongest basic protection?
Show answer & explanation
Correct answer: C - Strong wireless encryption with protected SSID and access controls
Domain 3: Endpoint Security Concepts - Describe operating system security concepts including Windows, macOS and Linux security features, Windows Defender, host-based firewalls, CLI, PowerShell, file and directory permissions and privilege escalation; demonstrate familiarity with endpoint tools that gather security assessment information including netstat, nslookup and tcpdump; verify endpoint systems meet security policies and standards including hardware inventory, asset management, software inventory, program deployment, data backups, PCI DSS, HIPAA, GDPR, BYOD device management, data encryption, app distribution and configuration management; implement software and hardware updates including Windows Update, application updates, device drivers, firmware and patching; interpret system logs including Event Viewer, audit logs, system and application logs, syslog and anomaly identification; demonstrate familiarity with malware removal including scanning systems, reviewing scan logs and malware remediation.
Question 6
A technician needs to identify currently established network connections on a workstation. Which tool is most appropriate?
Show answer & explanation
Correct answer: B - netstat
Question 7
A Windows workstation shows unauthorized software execution. Investigation reveals the user account has excessive permissions. Which issue should be addressed?
Show answer & explanation
Correct answer: A - Privilege escalation risk
Question 8
A technician reviews failed logins followed by a successful login from an unusual location. Which source provides the most relevant evidence?
Show answer & explanation
Correct answer: B - System and audit logs
Domain 4: Vulnerability Assessment and Risk Management - Explain vulnerability management including vulnerability identification, management and mitigation, active and passive reconnaissance and testing including port scanning and automation; use threat intelligence techniques to identify potential network vulnerabilities including uses and limitations of vulnerability databases, industry-standard tools, recommendations, policies and reports, Common Vulnerabilities and Exposures (CVEs), cybersecurity reports, cybersecurity news, subscription services, collective intelligence, ad hoc and automated threat intelligence, documentation updates, secure sharing and updating of documentation before, during and after cybersecurity incidents; explain risk management including vulnerability versus risk, ranking risks, approaches to risk management, risk mitigation strategies, risk levels, data classification risks and security assessments of IT systems; explain disaster recovery and business continuity planning including natural and human-caused disasters, DRP and BCP features, backup and disaster recovery controls.
Question 9
A vulnerability exists on an isolated server containing no sensitive information. Which factor is most important when determining risk?
Show answer & explanation
Correct answer: C - Potential impact and likelihood of exploitation
Question 10
A technician searches for publicly documented software weaknesses. Which resource tracks known vulnerabilities?
Domain 5: Incident Handling - Monitor security events and know when escalation is required including the role of SIEM and SOAR, monitoring network data for security incidents, packet captures, log file entries and identifying suspicious events; explain digital forensics and attack attribution processes including Cyber Kill Chain, MITRE ATT&CK Matrix, Diamond Model, Tactics, Techniques and Procedures (TTP), sources of evidence, artifacts, evidence preservation and chain of custody; explain the impact of compliance frameworks on incident handling including GDPR, HIPAA, PCI-DSS, FERPA and FISMA reporting and notification requirements; describe cybersecurity incident response elements including policies, plans, procedures and incident response lifecycle stages from NIST Special Publication 800-61 sections 2.3 and 3.1-3.4.
That's 10 of 1,030
The full bank has 1,020 more CCST-C questions with explanations.