
EC-CouncilCertified Cybersecurity Technician
Domain 1Objective 1
Information Security Threats and Vulnerabilities CCT Practice Questions (Page 7)
Part of the Information Security Threats and Attacks domain, which makes up ~12% of our current practice bank.
47questions here
10free pages
7concepts
Questions 31–35
- 31
A company has experienced multiple successful phishing attacks despite technical controls. The security team wants to reduce the likelihood of employees falling for these attacks. Which mitigation strategy would be most effective as a primary control?
Select an answer first - 32
Which of the following is a common output of a vulnerability scan?
Select an answer first - 33
A financial institution has detected a sophisticated attack that has been ongoing for six months. The attackers used zero-day exploits, custom malware, and compromised legitimate credentials to move laterally. They have been exfiltrating data slowly to avoid detection. Which threat actor type is most likely behind this attack?
Select an answer first - 34
A vulnerability assessment has been completed, and the report lists several vulnerabilities. The security team is reviewing the report and notices that some vulnerabilities are marked as 'false positives'. Which of the following is the most likely reason for a false positive?
Select an answer first - 35
A company has a mix of Windows and Linux servers. The security team wants to implement a mitigation strategy to reduce the risk of malware infections. Which of the following strategies would be most effective across both operating systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.