Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 5Objective 2

Explain Digital Forensics and Attack Attribution Processes 100-160 Practice Questions (Page 1)

Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 1–5

  1. 1expert · medium

    A security analyst is using the Diamond Model to analyze an intrusion. The analyst identifies that the adversary used a specific domain for command and control. Which element of the Diamond Model does the domain represent?

    Select an answer first
  2. 2expert · medium

    A forensic investigator is examining a compromised Windows system. The investigator needs to determine which programs were set to run automatically at startup. Which digital artifact would provide the MOST reliable evidence?

    Select an answer first
  3. 3application · medium

    A forensic investigator has collected a laptop from a suspect and needs to ensure the evidence is admissible in court. The investigator has documented who collected the evidence, when, and where. What additional step is essential to maintain the chain of custody?

    Select an answer first
  4. 4expert · hard

    An incident responder is analyzing a series of intrusions and notices that the same adversary has used different infrastructure (e.g., different domains and IPs) but the same malware family and similar TTPs. The responder wants to use the Diamond Model to link these intrusions. Which element is most useful for linking the intrusions to the same adversary?

    Select an answer first
  5. 5expert · hard

    A security team is analyzing an attack where the adversary used a previously unknown vulnerability in a web application, then used a legitimate system tool to move laterally, and finally encrypted files for ransom. The team wants to use MITRE ATT&CK to identify detection gaps. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.