Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 3Objective 5

Interpret System Logs 100-160 Practice Questions (Page 7)

Part of the Endpoint Security Concepts domain, which makes up ~25% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~5–9 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
6concepts

Questions 31–35

  1. 31expert · hard

    A security analyst is reviewing the Windows Security log and notices that a service account has been logging in successfully from a workstation in the marketing department every 15 minutes for the past hour. The service account is supposed to only be used by a specific application server. The analyst also sees that the application log on the application server shows no errors. What should the analyst do first?

    Select an answer first
  2. 32expert · hard

    A Windows application is crashing frequently, and the Application log shows Event ID 1000 with the faulting module 'ntdll.dll'. The application vendor suggests updating the application, but the IT team suspects a memory corruption issue. What should you do to gather more evidence?

    Select an answer first
  3. 33application · medium

    A network administrator is troubleshooting a syslog setup where the central server is not receiving logs from a switch. The switch is configured to send syslog to the server's IP address on UDP port 514. The administrator can ping the server from the switch. What should the administrator check next?

    Select an answer first
  4. 34application · medium

    A syslog analyst notices that a Linux server sends a 'sudo: user root : TTY=pts/0 ; PWD=/home/admin ; USER=root ; COMMAND=/bin/bash' message at 3:00 AM. The admin user is the only person with sudo rights, and they are on vacation. What should you do first?

    Select an answer first
  5. 35application · medium

    A user reports that they can access a sensitive file, but the security team wants to verify who has been reading it. You need to enable auditing for file access. What must you do in Windows to generate relevant events in the Security log?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.