Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 5Objective 4

Describe the Elements of Cybersecurity Incident Response 100-160 Practice Questions (Page 9)

Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
8concepts

Questions 41–45

  1. 41expert · medium

    A company is responding to a ransomware incident. The incident response team has identified the affected systems and wants to contain the spread. The team must decide between disconnecting the affected systems from the network and shutting them down. The forensic team needs to preserve evidence for a potential lawsuit. Which action should the team take?

    Select an answer first
  2. 42expert · medium

    A financial services firm is building its incident response capability. The firm has a limited budget and must choose between purchasing an expensive SIEM tool and conducting regular tabletop exercises. The firm's main concern is that its incident response team is new and lacks experience. Which choice best addresses the firm's concern?

    Select an answer first
  3. 43foundation · easy

    Which activity is part of the preparation stage of incident response?

    Select an answer first
  4. 44expert · medium

    A company's incident response plan includes a communication section that lists the incident response team, executives, and legal counsel. During a ransomware incident, the team discovers that the legal counsel's contact information is outdated, causing a delay in notifying the counsel. The team also realizes that the plan does not specify which systems are critical for business continuity. What is the most important improvement to make to the plan?

    Select an answer first
  5. 45application · medium

    A hospital is updating its incident response program. The compliance officer requires that all staff understand their specific duties during a security incident, and the IT team needs a documented procedure for isolating an infected workstation. Which combination of documents best satisfies these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.