
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 1
Monitor Security Events and Know When Escalation Is Required 100-160 Practice Questions (Page 7)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 31–35
- 31
Which factor is most important when determining whether a security event should be escalated to higher-level personnel?
Select an answer first - 32
What is the primary function of a Security Orchestration, Automation, and Response (SOAR) platform?
Select an answer first - 33
A security analyst detects a single failed login attempt on a user account. According to typical escalation criteria, what should the analyst do?
Select an answer first - 34
Which type of network data provides a detailed record of the actual content of traffic, including payloads?
Select an answer first - 35
A SIEM alert triggers when a single host performs a port scan of more than 100 ports on another host within a minute. The alert fires frequently for a vulnerability scanner that runs weekly. The security team wants to continue detecting real port scans but reduce false positives. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.