
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 1
Monitor Security Events and Know When Escalation Is Required 100-160 Practice Questions (Page 2)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 6–10
- 6
A network security team is investigating a possible malware infection. They have NetFlow data showing a host communicating with a known malicious IP. They also have full packet captures from the same period. The team wants to determine if the host downloaded a specific malware payload. Which data source should they analyze first?
Select an answer first - 7
A company has deployed a SIEM to collect logs from firewalls, servers, and applications. The security team wants to detect a multi-stage attack that involves a phishing email, a malicious download, and lateral movement. What is the primary benefit of using a SIEM for this detection?
Select an answer first - 8
A network analyst is investigating a potential data exfiltration incident. The analyst has access to NetFlow data and full packet captures. Which combination of data sources would provide the most comprehensive evidence for the investigation?
Select an answer first - 9
A SOC analyst receives an alert from the SIEM indicating that a single workstation has been sending large amounts of data to an external IP address that is not on any threat intelligence list. The workstation is used by a marketing employee who frequently uploads large files to a vendor's cloud service. What should the analyst do?
Select an answer first - 10
A small company's SIEM shows a single failed login event for a user account, followed by a successful login from the same IP address 30 seconds later. The user is currently online and reports no issues. The SOC analyst notices this pattern repeated for three other accounts from the same IP within the hour. According to the escalation criteria, what should the analyst do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.