Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 5Objective 1

Monitor Security Events and Know When Escalation Is Required 100-160 Practice Questions (Page 4)

Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A company has a SIEM that collects logs from multiple sources, but the security team is concerned about the high volume of false positives. They want to improve the accuracy of their alerts without increasing the workload on analysts. Which approach is most effective?

    Select an answer first
  2. 17expert · hard

    A security operations team wants to automate the response to common incidents, such as phishing emails, but they are concerned about the risk of automated actions causing unintended damage. They decide to implement a SOAR platform. Which configuration best balances automation with safety?

    Select an answer first
  3. 18application · medium

    A security analyst is reviewing the following security log entry from a Linux server: `Mar 15 02:14:22 server sshd[1234]: Failed password for root from 203.0.113.5 port 54321 ssh2` The same IP has appeared in 50 similar entries in the last 10 minutes. What should the analyst do first?

    Select an answer first
  4. 19application · medium

    A security operations center (SOC) receives thousands of alerts daily from its SIEM. Many are low-severity and require repetitive manual actions, such as blocking an IP address or resetting a password. The SOC manager wants to reduce analyst workload while ensuring that high-severity incidents still receive human review. Which approach best meets this requirement?

    Select an answer first
  5. 20application · medium

    A small company uses a SIEM to collect logs from its firewall, domain controller, and antivirus console. The SIEM generates an alert when a single workstation fails authentication five times within one minute. The security analyst notices that this alert fires frequently for a specific user who often mistypes passwords. The analyst wants to reduce noise while still detecting a potential brute-force attack. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.