
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 1
Monitor Security Events and Know When Escalation Is Required 100-160 Practice Questions (Page 3)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 11–15
- 11
Which capability is a defining feature of a SIEM that distinguishes it from a simple log management tool?
Select an answer first - 12
Which scenario best illustrates the use of SOAR in a security operations center?
Select an answer first - 13
A network administrator suspects that a workstation is communicating with a known command-and-control server. The administrator needs to determine whether any other hosts on the network have communicated with the same IP address over the past week. Which data source would be most efficient for this investigation?
Select an answer first - 14
A SOC analyst is handling an alert about a single failed login to a VPN service. The username is a standard user, and the source IP is a known coffee shop IP. The user is a frequent traveler and often connects from public Wi-Fi. The analyst has verified that the user is currently on a business trip. What should the analyst do?
Select an answer first - 15
What is the primary purpose of a Security Information and Event Management (SIEM) system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.