
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 4Objective 3
Explain Risk Management 100-160 Practice Questions (Page 4)
Part of the Vulnerability Assessment and Risk Management domain, which makes up ~20% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–7 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
Questions 16–20
- 16
A company has identified that its public-facing web server has a high likelihood of being compromised due to outdated software. The server is critical to business operations and cannot be taken offline. Which mitigation strategy would be most effective in reducing the risk while keeping the server operational?
Select an answer first - 17
A company has a limited security budget and must choose between fixing a vulnerability in a public-facing web server (high likelihood, medium impact) and a vulnerability in an internal HR database (low likelihood, high impact). The company has regulatory obligations to protect employee PII. Which risk should be prioritized?
Select an answer first - 18
A company stores sensitive customer data in a cloud environment. The company is considering moving to a new cloud provider that offers better security features but is more expensive. The current provider has had no breaches, but the company's security team believes the new provider's security controls are stronger. The company's budget is limited. What is the most balanced risk management decision?
Select an answer first - 19
A company's internal application has a known vulnerability that could allow an attacker to gain access to customer data. The vendor has released a patch, but the patch requires a reboot of the server, which would cause downtime during business hours. The company decides to apply the patch during the next maintenance window. Which risk mitigation strategy does this represent?
Select an answer first - 20
An organization is evaluating the risk of a ransomware attack on its file server. The file server contains only non-confidential operational data, and the organization has reliable backups. The likelihood of an attack is high, but the impact is low because data can be restored quickly. What is the overall risk level?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.