Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 5Objective 4

Describe the Elements of Cybersecurity Incident Response 100-160 Practice Questions (Page 8)

Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
8concepts

Questions 36–40

  1. 36application · medium

    After a phishing incident is fully contained and eradicated, the incident response team meets to discuss what went well and what could be improved. They create a report with action items, such as updating the email filtering rules and providing additional security awareness training. Which stage of the incident response lifecycle does this activity represent?

    Select an answer first
  2. 37application · medium

    A company's incident response plan says to 'contain the incident,' but the plan does not specify how to contain it. The team has a procedure that describes how to block a compromised host at the firewall. What is the relationship between the plan and the procedure?

    Select an answer first
  3. 38application · medium

    During a malware outbreak, the incident response team identifies that the malware communicates with an external command-and-control server. The team wants to stop the spread while preserving the ability to analyze the malware. Which action is the most appropriate containment strategy?

    Select an answer first
  4. 39application · medium

    A multinational company is drafting an incident response policy. The legal team requires that the policy clearly state which regulations apply to data breaches and who is responsible for notifying regulators. The security team wants the policy to define the boundaries of the incident response program. Which elements must the policy include to satisfy both requirements?

    Select an answer first
  5. 40foundation · easy

    What is the purpose of validating indicators of compromise (IOCs) during the detection and analysis stage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.