
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 2Objective 1
Describe TCP/IP Protocol Vulnerabilities 100-160 Practice Questions (Page 8)
Part of the Basic Network Security Concepts domain, which makes up ~19% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–7 in this domain), expect 1–1 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 36–40
- 36
A security analyst is evaluating the risk of a DNS amplification attack on the company's public-facing DNS server. The server is configured to allow recursion for external clients. The analyst wants to reduce the risk without affecting legitimate external queries. Which two measures should the analyst implement?
Select an answer first - 37
A network administrator is responsible for a network that uses both DHCP and static IP addressing. The administrator wants to implement a defense against ARP spoofing, but the network has some devices that do not support DHCP snooping. Which approach is most effective while minimizing administrative overhead?
Select an answer first - 38
A network administrator is troubleshooting a network outage. The administrator sees a large volume of ICMP echo requests on the network, but the source IPs are all different and appear to be legitimate. The administrator also notices that the router's CPU usage is high and that the router is dropping packets. Which two actions should the administrator take to mitigate the attack?
Select an answer first - 39
A network administrator is configuring a firewall to protect a web server from common TCP-based attacks. The administrator wants to prevent SYN floods while still allowing legitimate connections. Which configuration is most appropriate?
Select an answer first - 40
A network technician notices that a user's workstation cannot reach the internet, but other workstations on the same subnet can. The technician runs `arp -a` on the affected workstation and sees an entry for the default gateway with an incorrect MAC address. Which attack is most likely occurring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.