Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 5Objective 4

Describe the Elements of Cybersecurity Incident Response 100-160 Practice Questions (Page 4)

Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    In an incident response plan, what is the main purpose of the 'preparation' component?

    Select an answer first
  2. 17expert · medium

    After a phishing incident, the incident response team conducts a lessons-learned meeting. The team identifies that the phishing email bypassed the email filter because the filter was not configured to detect the specific attachment type. The team decides to update the email filter rules and revise the incident response plan to include a step for reviewing filter configurations. Which two post-incident activities are the team performing?

    Select an answer first
  3. 18application · medium

    A company experienced a data breach that was traced to an unpatched vulnerability in a public-facing web server. After the incident is resolved, the security team wants to prevent a recurrence. Which post-incident activity is most directly aimed at this goal?

    Select an answer first
  4. 19application · medium

    A regional bank has an incident response plan that lists the incident response team and their contact information, but the plan does not specify which systems are in scope or how to prioritize containment efforts. During a ransomware event, the team spends time debating whether to isolate the file server or the domain controller first. Which component is most clearly missing from the plan?

    Select an answer first
  5. 20expert · hard

    A hospital is updating its incident response plan. The compliance officer requires that the plan clearly define who is responsible for notifying regulators in case of a data breach. The security team wants the plan to include a step-by-step procedure for isolating an infected workstation. The plan currently only lists high-level actions. What is the most appropriate way to satisfy both requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.