
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 4
Describe the Elements of Cybersecurity Incident Response 100-160 Practice Questions (Page 10)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
Questions 46–50
- 46
A security analyst is documenting the timeline of an incident: initial alert, validation, containment, eradication, recovery, and the final review meeting. The analyst wants to map these actions to the NIST SP 800-61 lifecycle stages. Which mapping is correct?
Select an answer first - 47
What is a key goal of the preparation stage in incident response?
Select an answer first - 48
Which component of an incident response plan involves restoring systems to normal operation?
Select an answer first - 49
A company is building its incident response capability from scratch. The CISO wants to ensure that the team has the right tools, trained personnel, and documented policies before any incident occurs. Which stage of the NIST incident response lifecycle is the company currently in?
Select an answer first - 50
A university is creating an incident response policy. The policy must define which departments are covered, who is responsible for leading the response, and what legal and regulatory obligations must be met. Which two elements are most essential to include in the policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.