
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 2
Explain Digital Forensics and Attack Attribution Processes 100-160 Practice Questions (Page 6)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 26–30
- 26
In the Diamond Model of Intrusion Analysis, which core feature represents the person or group behind an attack?
Select an answer first - 27
Which of the following is an example of a digital artifact that could be found on a Windows system?
Select an answer first - 28
A forensic analyst is collecting evidence from a running Windows system. The analyst needs to capture the contents of RAM before powering down the system. Which tool or method is MOST appropriate?
Select an answer first - 29
A forensic investigator is examining a compromised Linux server. The investigator wants to find evidence of unauthorized access, including which commands were run and which files were accessed. Which two sources of digital evidence would be most useful?
Select an answer first - 30
A security analyst is reviewing an incident where an attacker delivered a malicious USB drive to a receptionist, who plugged it into a computer, which then installed malware that connected to an external server. The analyst wants to map this to the Cyber Kill Chain. Which two phases are most directly illustrated by the USB delivery and the malware installation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.