
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 2Objective 1
Describe TCP/IP Protocol Vulnerabilities 100-160 Practice Questions (Page 5)
Part of the Basic Network Security Concepts domain, which makes up ~19% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–7 in this domain), expect 1–1 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 21–25
- 21
A network administrator is implementing DHCP snooping and Dynamic ARP Inspection (DAI) on a network that also uses static IP addresses for servers. The administrator wants to ensure that the servers are not affected by ARP spoofing. Which configuration is necessary?
Select an answer first - 22
Which vulnerability is inherent to HTTP because it transmits data in plaintext?
Select an answer first - 23
A network administrator is configuring a firewall to prevent ICMP-based denial-of-service attacks while still allowing network troubleshooting. Which rule set is most appropriate?
Select an answer first - 24
Which DHCP attack involves an attacker sending many DHCP discover messages with spoofed MAC addresses to exhaust the DHCP server's address pool?
Select an answer first - 25
A security engineer is designing a DDoS mitigation strategy for a public-facing application. The application uses both TCP (for HTTPS) and UDP (for a custom protocol). The engineer needs to protect against SYN floods, UDP amplification, and ICMP floods, but must minimize latency for legitimate users. Which combination of mitigations is most balanced?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.