
EC-CouncilCertified Cybersecurity Technician
Domain 1Objective 1
Information Security Threats and Vulnerabilities CCT Practice Questions (Page 6)
Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.
47questions here
10free pages
7concepts
Questions 26–30
- 26
Which of the following is a basic mitigation strategy for addressing software vulnerabilities?
Select an answer first - 27
A company allows employees to connect personal smartphones to the corporate Wi-Fi network. The security team is concerned about the increased attack surface. Which of the following is the most direct attack vector introduced by this practice?
Select an answer first - 28
A security team is analyzing a series of attacks against a financial institution. The attacks have been ongoing for six months and involve sophisticated custom malware, targeted spear-phishing, and lateral movement. The attackers appear to be well-funded and are likely sponsored by a foreign government. The goal seems to be long-term intelligence gathering. Which of the following best describes this type of threat?
Select an answer first - 29
A security analyst is investigating a data breach. The investigation reveals that an employee with legitimate access to customer data exfiltrated the data to a competitor for financial gain. How should the analyst classify this threat actor?
Select an answer first - 30
A vulnerability scan reveals that a database server has a critical remote code execution vulnerability. The server is only accessible from the internal network, and the data it holds is not considered sensitive. The organization has a limited budget for remediation. Which action best balances risk and cost?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.