Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 1Objective 1

Information Security Threats and Vulnerabilities CCT Practice Questions (Page 3)

Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.

47questions here
10free pages
7concepts

Questions 11–15

  1. 11application · medium

    A company is concerned about the risk of malware infections from employees downloading files from the internet. Which of the following is the most effective mitigation strategy to reduce this risk?

    Select an answer first
  2. 12application · medium

    A vulnerability scan of a web server reports that the server is running an outdated version of OpenSSL with a known critical vulnerability. The server is behind a firewall that blocks all inbound traffic except HTTPS on port 443, and the vulnerability is only exploitable through a local shell. The security team is preparing a risk report. How should the team characterize this finding?

    Select an answer first
  3. 13application · medium

    A security analyst observes that a user's workstation is sending a large volume of encrypted data to an external IP address during off-hours. The user is unaware of any unusual activity. Which type of threat is most likely occurring?

    Select an answer first
  4. 14expert · hard

    A security analyst is profiling a threat actor who has been conducting low-level attacks against multiple organizations. The actor uses publicly available tools and follows known exploit tutorials. Their attacks are often noisy and easily detected. The motivation appears to be gaining recognition or simply causing disruption. How should the analyst classify this threat actor?

    Select an answer first
  5. 15expert · hard

    A company has discovered that a former employee, who was laid off, still has valid credentials to the corporate network. The employee has not used them since termination, but the credentials were not revoked. Which threat actor type does this situation most closely resemble?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.