
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 1Objective 2
Explain Common Threats and Vulnerabilities 100-160 Practice Questions (Page 5)
Part of the Essential Security Principles domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 21–25
- 21
A company's website is hit by a DDoS attack that overwhelms its internet connection. The attack traffic originates from a botnet of compromised IoT devices. The company wants to keep the website available for legitimate users. Which mitigation strategy is most effective in this scenario?
Select an answer first - 22
A user on a public Wi-Fi network at a coffee shop logs into their bank account. Later, they notice unauthorized transactions. The attacker had set up a rogue access point with the same name as the coffee shop's Wi-Fi. Which attack did the user fall victim to, and what is the best defense?
Select an answer first - 23
A security team is investigating a breach where an attacker has been present in the network for over a year. The attacker used legitimate credentials, moved laterally between systems, and exfiltrated data slowly to avoid detection. The attacker's objective appears to be intellectual property theft. Which characteristic most clearly distinguishes this as an APT rather than a typical cybercriminal attack?
Select an answer first - 24
A network administrator is troubleshooting a user's complaint that their web sessions are being redirected to fake login pages. The administrator checks the ARP cache on the user's machine and finds that the gateway's MAC address has changed. Which attack has occurred, and what is the most effective mitigation?
Select an answer first - 25
A security team is investigating a breach where an attacker maintained access for over a year, using legitimate credentials and moving slowly to avoid detection. The attacker's goal was to steal research data. Which characteristic most clearly distinguishes this as an APT rather than a typical malware infection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.