Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 3Objective 6

Demonstrate Familiarity with Malware Removal 100-160 Practice Questions (Page 4)

Part of the Endpoint Security Concepts domain, which makes up ~25% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~5–9 in this domain), expect 1–2 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 16–20

  1. 16application · medium

    A scan log shows the following entry: 'Threat: Trojan.Win32.Emotet, Severity: High, File: C:\Users\jdoe\AppData\Local\Temp\svchost.exe, Action: Quarantine successful.' The administrator notices that the file path is in the user's Temp folder and the file name mimics a legitimate Windows process. What should the administrator do NEXT?

    Select an answer first
  2. 17application · medium

    After removing a keylogger from a user's workstation, the admin wants to ensure that the keylogger has not captured sensitive data that could be exfiltrated. Which post-remediation action is most important?

    Select an answer first
  3. 18expert · hard

    A scan log shows the following entry: 'Threat: Spyware.Agent, Severity: Medium, File: C:\Users\Public\AppData\Roaming\helper.dll, Action: Quarantined, Status: Deleted'. The analyst also sees that the file was associated with a process named 'helper.exe' that is no longer running. What should the analyst do next?

    Select an answer first
  4. 19expert · hard

    After removing a piece of malware from a user's workstation, the admin has run a full scan and found no threats. However, the admin notices that the workstation's hosts file has been modified and contains entries redirecting known banking sites to a malicious IP. What should the admin do?

    Select an answer first
  5. 20expert · hard

    A company's endpoint detection and response (EDR) tool flags a benign-looking PowerShell script that is scheduled to run daily. The script downloads a file from an external URL and executes it. The script is signed by a legitimate internal developer. The EDR blocks the script, but the developer insists it is a legitimate automation task. What is the best course of action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.