Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 4Objective 2

Use Threat Intelligence Techniques to Identify Potential Network Vulnerabilities 100-160 Practice Questions (Page 11)

Part of the Vulnerability Assessment and Risk Management domain, which makes up ~20% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–7 in this domain), expect 1–2 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
10concepts

Questions 51–55

  1. 51application · medium

    A company wants to continuously identify vulnerabilities in its cloud infrastructure. The security team is small and cannot manually review every new CVE. They need a solution that automatically checks their cloud resources against known vulnerabilities and provides a dashboard for tracking remediation. Which approach best meets this need?

    Select an answer first
  2. 52expert · hard

    A security analyst is using the NVD to research a vulnerability that was disclosed in a third-party library. The NVD entry shows a CVSS score of 7.5, but the analyst finds a vendor advisory that rates the same vulnerability as 'high' with a different CVSS score. The analyst also sees that a commercial threat intelligence feed lists the vulnerability as 'exploited in the wild.' The organization uses the library in a non-internet-facing application. What should the analyst do to prioritize remediation?

    Select an answer first
  3. 53application · medium

    A small business cannot afford commercial threat intelligence feeds. The IT admin wants to use ad hoc methods to identify potential vulnerabilities. Which approach is an example of ad hoc threat intelligence?

    Select an answer first
  4. 54application · medium

    A vulnerability management team is using the NVD to track a newly disclosed vulnerability. They notice that the NVD entry does not yet include a CVSS score or any references. What is the most appropriate action?

    Select an answer first
  5. 55application · medium

    A security analyst is reading a threat intelligence report that mentions a new malware family targeting a specific type of IoT device. The report includes a list of CVE IDs associated with the malware. Which action best uses this report to improve the organization's security posture?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.