
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 3Objective 5
Interpret System Logs 100-160 Practice Questions (Page 5)
Part of the Endpoint Security Concepts domain, which makes up ~25% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~5–9 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 21–25
- 21
What is the primary purpose of the syslog protocol?
Select an answer first - 22
A Windows administrator needs to review the event logs to troubleshoot a recent application crash. Which built-in Windows tool should they use?
Select an answer first - 23
An administrator notices that a user account that normally logs in only during business hours has a successful logon at 3:00 AM. What type of anomaly does this represent?
Select an answer first - 24
A security analyst is investigating a potential data breach. The analyst needs to determine which files were accessed by a specific user account. Which audit policy and log should the analyst use?
Select an answer first - 25
A security analyst is reviewing syslog messages from multiple devices and notices that a user account has been successfully logging into a Linux server via SSH at 2:00 AM every day for the past week. The account is a standard user account. The analyst also sees that the same account has been failing to log into a Windows server at 2:05 AM. Which conclusion is most justified?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.