
EC-CouncilCertified Cybersecurity Technician
Domain 1Objective 1
Information Security Threats and Vulnerabilities CCT Practice Questions (Page 1)
Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.
47questions here
10free pages
7concepts
Questions 1–5
- 1
A small manufacturing company's IT team notices repeated login attempts against its public-facing VPN gateway from a range of IP addresses that trace back to a known cybercriminal forum. The attempts are low-volume but persistent over several weeks, and no data has been exfiltrated. The company's leadership wants to understand the likely intent behind these attempts before deciding on a response. Which characterization best fits this activity?
Select an answer first - 2
A vulnerability assessment has been completed, and the report lists several vulnerabilities with different severity ratings. The security team has limited resources to fix them. Which of the following should be the primary factor in deciding which vulnerabilities to remediate first?
Select an answer first - 3
Which statement correctly defines risk in the context of information security?
Select an answer first - 4
A vulnerability scan reveals a critical remote code execution vulnerability in a legacy application that is no longer supported by the vendor. The application is used by the finance department and cannot be taken offline during business hours. Which of the following is the most appropriate risk treatment option?
Select an answer first - 5
A company's security team is reviewing its attack surface. They find that a legacy application is accessible from the internet and has known unpatched vulnerabilities. The application is not business-critical and is used by only a few employees. Which action would most effectively reduce the attack surface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.