Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 3Objective 2

Demonstrate Familiarity with Appropriate Endpoint Tools That Gather Security Assessment Information 100-160 Practice Questions (Page 3)

Part of the Endpoint Security Concepts domain, which makes up ~25% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~5–9 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
3concepts

Questions 11–15

  1. 11expert · hard

    A security analyst is investigating a Linux server that is suspected of being part of a botnet. The analyst needs to identify the process that is making outbound connections to a known command-and-control server and then capture the traffic to that server for analysis. The server has multiple users and the analyst has root access. Which approach is most effective?

    Select an answer first
  2. 12application · medium

    A security analyst is verifying that a company's mail server hostname resolves to the correct IP address after a recent DNS change. The analyst wants to query the authoritative DNS server directly, bypassing the local cache. Which command should be used?

    Select an answer first
  3. 13application · medium

    A security analyst is verifying the DNS configuration of a domain after a suspected DNS hijack. The analyst needs to confirm the IP address that the domain currently resolves to and compare it against the expected value. Which command should be used?

    Select an answer first
  4. 14foundation · easy

    An analyst is investigating a potential DNS issue and wants to see the mail exchanger (MX) records for a domain. Which nslookup command sequence is appropriate?

    Select an answer first
  5. 15expert · hard

    A security analyst is responding to a suspected malware infection on a Windows server. The analyst needs to identify which process is listening on a suspicious port and then capture the traffic to that port to determine if it is malicious. The analyst has administrative privileges. Which sequence of commands is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.