Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Support Technician (CCST) Cybersecurity

Domain 4Objective 2

Use Threat Intelligence Techniques to Identify Potential Network Vulnerabilities 100-160 Practice Questions (Page 8)

Part of the Vulnerability Assessment and Risk Management domain, which makes up ~20% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–7 in this domain), expect 1–2 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
10concepts

Questions 36–40

  1. 36foundation · easy

    What is a best practice for securing documentation that contains sensitive information?

    Select an answer first
  2. 37application · medium

    A security analyst is reviewing a newly published CVE for a web application framework used by the company. The CVE entry lists a CVSS score of 9.8 and states that exploitation is 'possible remotely without authentication.' However, the analyst notices the CVE was published only 24 hours ago and the vendor has not yet released a patch. The analyst must decide how to prioritize this vulnerability in the remediation queue. What is the most appropriate action based on threat intelligence best practices?

    Select an answer first
  3. 38expert · hard

    A network administrator hears from a colleague at another company about a zero-day vulnerability in a network switch model that the administrator's company also uses. The colleague says the vendor is aware but has not released a patch. The administrator wants to protect the network while waiting for the patch. The administrator has limited authority to make changes and must document any actions. What is the most appropriate course of action?

    Select an answer first
  4. 39expert · hard

    A security operations center (SOC) uses an automated vulnerability management platform that ingests threat intelligence feeds and scans the network daily. The platform generates a large number of alerts, many of which are false positives. The SOC team is overwhelmed and is considering disabling some automated features. What is the best way to improve the efficiency of the automated threat intelligence process?

    Select an answer first
  5. 40expert · hard

    A security analyst is monitoring multiple threat intelligence sources for information about a new ransomware campaign. A commercial feed reports that the campaign targets a specific VPN appliance, while a free blog claims it targets a different product. The analyst also sees a post on a social media forum from an unknown user claiming the campaign is a hoax. The organization uses both VPN products. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.