CiscoAssociate level100-160

100-160 exam dumps: 265 free Cisco CCST Cybersecurity practice questions

Free 100-160 practice questions for the Cisco Certified Support Technician (CCST) Cybersecurity exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 265 by number, or take a timed practice exam.

Question bank last updated January 2025

Free 100-160 practice questions

Questions 1 to 10 of 265

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

100-160 Question 1

Select 3

A company is implementing a new security policy to protect sensitive data. The IT team has decided to follow the principle of 'least privilege' across all systems and users. Which of the following actions align with this principle?

  1. A

    Granting users access only to the files and systems they need to perform their job responsibilities

  2. B

    Providing administrative privileges to all employees to ensure they can troubleshoot their own issues

  3. C

    Regularly reviewing user access permissions and revoking access no longer required

  4. D

    Allowing temporary access to additional systems for users who have specific, time-bound tasks

  5. E

    Enabling unrestricted access to shared resources for all users to encourage collaboration

Show answer and explanation

Correct answers: A, C, D

Explanation

The principle of least privilege ensures that users only have access to the resources and systems necessary for their specific tasks. This minimizes the risk of accidental or intentional misuse of systems and data. Actions like restricting access, reviewing permissions, and allowing temporary access for specific tasks align with this principle, while providing unnecessary privileges or unrestricted access does not.

  • A. Correct.

    Correct: Limiting user access strictly to what is necessary for their role directly aligns with the principle of least privilege.

  • B. Incorrect.

    Incorrect: Granting administrative privileges to all employees violates the principle of least privilege by giving unnecessary access rights.

  • C. Correct.

    Correct: Regularly reviewing and revoking unnecessary permissions ensures that access levels remain appropriate and minimizes security risks.

  • D. Correct.

    Correct: Allowing temporary access for specific, time-bound tasks supports the principle of least privilege while addressing business needs.

  • E. Incorrect.

    Incorrect: Unrestricted access to shared resources can expose sensitive data to unauthorized users, which goes against the principle of least privilege.

100-160 Question 2

Single answer

A company recently experienced a data breach due to an employee using the same password across multiple systems. As a cybersecurity support technician, which essential security principle should you prioritize to mitigate this risk?

  1. A

    Implementing multi-factor authentication (MFA)

  2. B

    Enforcing a strong password policy and regular password changes

  3. C

    Enabling firewall rules for all external traffic

  4. D

    Conducting regular phishing awareness training

Show answer and explanation

Correct answer: B

Explanation

Password reuse is a common vulnerability that can lead to data breaches if credentials are compromised. Enforcing a strong password policy and requiring regular password changes ensures employees use different and secure passwords for each system, reducing the risk of unauthorized access. While other options enhance security in different areas, they do not specifically address the issue of password reuse.

  • A. Incorrect.

    Implementing multi-factor authentication (MFA) adds an extra layer of security, but it does not directly address the issue of password reuse across multiple systems.

  • B. Correct.

    Enforcing a strong password policy and regular password changes directly mitigates the risk of password reuse, ensuring that employees use unique and secure passwords for each system.

  • C. Incorrect.

    Enabling firewall rules for external traffic enhances network security but is not directly related to mitigating the risks associated with password reuse.

  • D. Incorrect.

    Phishing awareness training is essential for preventing social engineering attacks but does not address the issue of password reuse.

100-160 Question 3

Select 3

A company has recently adopted a Bring Your Own Device (BYOD) policy, allowing employees to use personal devices to access corporate resources. As part of essential security principles, which measures should be implemented to maintain security in such an environment?

  1. A

    Enforce strong password requirements on all devices accessing corporate resources

  2. B

    Allow unrestricted access to corporate resources to support productivity

  3. C

    Implement Mobile Device Management (MDM) to control and secure employee devices

  4. D

    Disable two-factor authentication (2FA) on personal devices to simplify access

  5. E

    Educate employees on secure usage and potential risks associated with personal devices

Show answer and explanation

Correct answers: A, C, E

Explanation

The essential security principles for handling BYOD environments include enforcing strong authentication mechanisms like passwords, implementing tools like Mobile Device Management (MDM) to maintain control and security over devices, and educating employees to recognize potential risks. These measures collectively reduce vulnerabilities while enabling secure access to corporate resources. Disabling 2FA or allowing unrestricted access contradicts these principles and can expose the organization to significant risks.

  • A. Correct.

    Strong password requirements are essential to prevent unauthorized access and ensure that corporate resources are adequately protected.

  • B. Incorrect.

    Unrestricted access to corporate resources increases the attack surface and goes against essential security principles, which emphasize access control and least privilege.

  • C. Correct.

    Mobile Device Management (MDM) is a critical tool in securing personal devices and ensuring compliance with organizational security policies.

  • D. Incorrect.

    Disabling two-factor authentication reduces security and increases the risk of unauthorized access, violating the principle of layered security.

  • E. Correct.

    Educating employees increases awareness of potential risks and helps them adopt secure practices, which is a fundamental aspect of essential security principles.

100-160 Question 4

Select 2

Your organization has recently implemented a new file-sharing service for employees. As a cybersecurity technician, you recommend applying the principle of 'least privilege' to ensure security. Which of the following actions best align with this principle?

  1. A

    Grant users access only to the files they need to perform their job duties.

  2. B

    Provide all employees administrative access to the file-sharing system to ensure operational flexibility.

  3. C

    Regularly review and revoke access for users who no longer need it.

  4. D

    Allow temporary contractors unrestricted access to all files to avoid delays in their onboarding process.

  5. E

    Require strong passwords and multi-factor authentication for accessing the system.

Show answer and explanation

Correct answers: A, C

Explanation

The principle of 'least privilege' ensures that users have only the minimum level of access necessary to perform their work. Granting minimal access and regularly reviewing permissions help reduce the risk of unauthorized access or misuse of resources. Options 1 and 3 align with this principle, while the other options either violate it or are unrelated.

  • A. Correct.

    Granting users access only to the files they need to perform their job duties aligns with the principle of least privilege by minimizing access to only what is necessary.

  • B. Incorrect.

    Providing all employees administrative access violates the principle of least privilege, as it grants excessive permissions that can increase the risk of unauthorized actions or breaches.

  • C. Correct.

    Regularly reviewing and revoking access for users who no longer need it ensures that unnecessary privileges are removed, maintaining alignment with the principle of least privilege.

  • D. Incorrect.

    Allowing temporary contractors unrestricted access to all files violates the principle of least privilege by providing excessive access beyond what is necessary for their role.

  • E. Incorrect.

    Requiring strong passwords and multi-factor authentication is a good security practice but is not directly related to the principle of least privilege, which focuses on limiting access rights.

100-160 Question 5

Single answer

A small business is implementing a cybersecurity strategy for the first time. The IT manager emphasizes the importance of the principle of 'least privilege.' Which of the following actions best aligns with this principle?

  1. A

    Granting all employees administrative access to ensure they can complete their tasks without delays

  2. B

    Restricting access rights for users to only the resources and permissions necessary for their roles

  3. C

    Allowing team leaders unrestricted access to all systems and data to monitor their team’s activities

  4. D

    Creating a shared administrative account for all employees to use for elevated access when needed

Show answer and explanation

Correct answer: B

Explanation

The principle of 'least privilege' ensures users and systems are granted only the permissions they need to perform their tasks, reducing the attack surface and minimizing the risk of unauthorized actions. Option 2 correctly applies this principle by restricting access based on role requirements, while the other options provide excessive or inappropriate permissions.

  • A. Incorrect.

    Granting administrative access to all employees violates the principle of least privilege because it provides more access than necessary, increasing the risk of accidental or malicious misuse.

  • B. Correct.

    Restricting access rights to only what is necessary for a user’s role aligns with the principle of least privilege, minimizing the potential for misuse or compromise.

  • C. Incorrect.

    Unrestricted access for team leaders goes beyond the necessary permissions for their roles, violating the principle of least privilege.

  • D. Incorrect.

    Shared administrative accounts pose a security risk due to lack of accountability and violate the principle of least privilege by potentially granting excessive access.

100-160 Question 6

Select 3

An organization wants to implement a security strategy for its network infrastructure. The security team decides to apply the principles of 'least privilege' and 'defense in depth.' Which of the following actions align with these security principles?

  1. A

    Grant users access only to the resources they need to perform their job functions.

  2. B

    Deploy multiple layers of security controls, such as firewalls, intrusion detection systems, and endpoint protection.

  3. C

    Provide all employees with administrative privileges to ensure they can troubleshoot issues independently.

  4. D

    Rely solely on a single firewall for network protection to reduce complexity.

  5. E

    Regularly review and update access permissions to ensure they align with job responsibilities.

Show answer and explanation

Correct answers: A, B, E

Explanation

The principles of 'least privilege' and 'defense in depth' are fundamental to cybersecurity. 'Least privilege' ensures users only have the minimum access necessary to perform their work, reducing risks of misuse. 'Defense in depth' employs multiple layers of security to protect against various threats, ensuring no single point of failure compromises the system. Correctly applying these principles strengthens an organization's overall security posture.

  • A. Correct.

    Granting users access only to the resources they need aligns with the principle of 'least privilege,' which minimizes the risk of unauthorized access or misuse.

  • B. Correct.

    Deploying multiple layers of security controls aligns with the principle of 'defense in depth,' ensuring that if one security layer is breached, others remain effective.

  • C. Incorrect.

    Providing all employees with administrative privileges violates the principle of 'least privilege,' as it unnecessarily increases the risk of privilege abuse or accidental system changes.

  • D. Incorrect.

    Relying solely on a single firewall for protection does not align with 'defense in depth,' as it introduces a single point of failure in the security strategy.

  • E. Correct.

    Regularly reviewing and updating access permissions ensures the principle of 'least privilege' is maintained over time, reducing the risk of unnecessary access.

100-160 Question 7

Single answer

A company has implemented a new policy to ensure that only authorized users can access sensitive financial data. To enforce this, they require all employees to use multi-factor authentication (MFA) when accessing the financial system. Which essential security principle is being applied in this scenario?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Availability

  4. D

    Non-repudiation

Show answer and explanation

Correct answer: A

Explanation

The use of multi-factor authentication is a direct application of the confidentiality principle. It ensures that sensitive data is protected from unauthorized access, which is a fundamental aspect of cybersecurity.

  • A. Correct.

    Confidentiality involves protecting sensitive information from unauthorized access. By requiring multi-factor authentication, the company ensures that only authorized users can access the financial data, aligning with this principle.

  • B. Incorrect.

    Integrity refers to ensuring that data remains accurate and unaltered during storage or transmission. While important, this principle is not directly addressed by the use of multi-factor authentication in this scenario.

  • C. Incorrect.

    Availability ensures that data and systems are accessible when needed. Although critical for security, this principle is not the focus of the scenario provided.

  • D. Incorrect.

    Non-repudiation ensures that actions or transactions cannot be denied by the party involved. This principle does not directly relate to the use of multi-factor authentication in this case.

100-160 Question 8

Select 4

A company is implementing security measures to protect its data and systems. The IT manager emphasizes the importance of confidentiality, integrity, and availability when designing these measures. Which of the following actions align with these essential security principles?

  1. A

    Encrypting sensitive files before storage to prevent unauthorized access

  2. B

    Regularly backing up data to ensure it can be restored in case of a failure

  3. C

    Using multi-factor authentication to restrict access to critical systems

  4. D

    Allowing employees to share their passwords for easier collaboration

  5. E

    Monitoring system logs for suspicious activities to detect potential breaches

Show answer and explanation

Correct answers: A, B, C, E

Explanation

The essential security principles of confidentiality, integrity, and availability (CIA triad) guide the design of security measures. Confidentiality ensures that sensitive information is protected from unauthorized access, integrity ensures data accuracy and trustworthiness, and availability ensures that authorized users can access systems and data when needed. Actions like encryption, backups, multi-factor authentication, and log monitoring align with these principles. However, sharing passwords undermines security and violates the CIA triad.

  • A. Correct.

    Encrypting sensitive files ensures confidentiality by preventing unauthorized access to data.

  • B. Correct.

    Regularly backing up data supports availability by ensuring recovery in case of data loss or system failure.

  • C. Correct.

    Using multi-factor authentication enhances confidentiality by ensuring that only authorized users can access critical systems.

  • D. Incorrect.

    Allowing employees to share passwords violates confidentiality and increases the risk of unauthorized access.

  • E. Correct.

    Monitoring system logs helps maintain integrity by identifying potential breaches or unauthorized changes in a timely manner.

100-160 Question 9

Single answer

A company implements a password policy requiring employees to change their passwords every 90 days, use complex passwords with a mix of characters, and avoid reusing previous passwords. Which essential security principle does this policy primarily address?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Availability

  4. D

    Authentication

Show answer and explanation

Correct answer: A

Explanation

The password policy described enforces strong security measures to prevent unauthorized access to sensitive information, aligning with the principle of confidentiality. By requiring complex passwords, avoiding reuse, and periodic changes, the policy reduces the risk of information being exposed to unauthorized individuals.

  • A. Correct.

    Confidentiality is the principle of ensuring that sensitive information is accessible only to authorized individuals. A strong password policy helps prevent unauthorized access, maintaining confidentiality.

  • B. Incorrect.

    Integrity refers to ensuring the accuracy and reliability of data. While important, this principle is not directly addressed by the password policy described.

  • C. Incorrect.

    Availability ensures that information and systems are accessible to authorized users when needed. This policy does not directly relate to keeping systems or data available.

  • D. Incorrect.

    Authentication is the process of verifying the identity of a user or system. While passwords are a part of authentication, the described policy focuses on protecting data confidentiality rather than the authentication process itself.

100-160 Question 10

Single answer

A company has implemented a new access control system to ensure that employees can only access resources necessary for their job roles. Which essential security principle is primarily being applied in this scenario?

  1. A

    Least Privilege

  2. B

    Confidentiality

  3. C

    Defense in Depth

  4. D

    Non-repudiation

Show answer and explanation

Correct answer: A

Explanation

The principle of least privilege is fundamental to cybersecurity and ensures that users are granted only the permissions necessary to perform their job functions, minimizing potential security risks. In this scenario, the new access control system enforces this principle by limiting employees' access to only the resources they need.

  • A. Correct.

    The principle of least privilege ensures that users have access only to the resources required for their specific job roles, reducing the risk of unauthorized access.

  • B. Incorrect.

    Confidentiality refers to protecting sensitive information from being accessed by unauthorized individuals, which is not the primary focus of the scenario.

  • C. Incorrect.

    Defense in Depth involves layering multiple security controls to create a comprehensive defense strategy, but it is not directly related to access control in this context.

  • D. Incorrect.

    Non-repudiation ensures that actions or transactions cannot be denied later, which does not apply to the described access control system.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

All 265 100-160 practice questions

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them.

  1. 1.A company is implementing a new security policy to protect sensitive data. The IT team has decided to follow...
  2. 2.A company recently experienced a data breach due to an employee using the same password across multiple...
  3. 3.A company has recently adopted a Bring Your Own Device (BYOD) policy, allowing employees to use personal...
  4. 4.Your organization has recently implemented a new file-sharing service for employees. As a cybersecurity...
  5. 5.A small business is implementing a cybersecurity strategy for the first time. The IT manager emphasizes the...
  6. 6.An organization wants to implement a security strategy for its network infrastructure. The security team...
  7. 7.A company has implemented a new policy to ensure that only authorized users can access sensitive financial...
  8. 8.A company is implementing security measures to protect its data and systems. The IT manager emphasizes the...
  9. 9.A company implements a password policy requiring employees to change their passwords every 90 days, use...
  10. 10.A company has implemented a new access control system to ensure that employees can only access resources...
  11. 11.A financial services company has recently experienced a data breach where attackers exploited a vulnerability...
  12. 12.A company recently experienced a ransomware attack that encrypted critical business data. Upon investigation,...
  13. 13.An organization recently experienced a data breach where an attacker exploited an unpatched vulnerability in...
  14. 14.A company's web server was compromised, and a malicious actor exploited a code vulnerability to gain...
  15. 15.A company recently experienced a ransomware attack that exploited a known software vulnerability. Upon...
  16. 16.A user within your organization reports receiving an email claiming to be from your IT department, requesting...
  17. 17.A company’s cybersecurity team discovers that multiple employees have been receiving phishing emails designed...
  18. 18.A small business has recently experienced a ransomware attack that encrypted all its critical files. Upon...
  19. 19.A small company's IT administrator discovers unusual outbound traffic from one of their servers, which is...
  20. 20.An employee in your organization clicks on a link in a phishing email, which downloads malware onto their...
  21. 21.A company’s IT team notices unusual outbound traffic from several devices on the network. Upon investigation,...
  22. 22.A financial services company has detected unusual outbound traffic from an employee's workstation. Further...
  23. 23.A company's IT team detects unusual outbound traffic from multiple employee devices to an unknown external IP...
  24. 24.An employee at a company receives an email that appears to be from their IT department, requesting them to...
  25. 25.A company has recently experienced a ransomware attack that encrypted critical files and demanded payment in...
  26. 26.A company is implementing a new access management system to secure its sensitive data. The system requires...
  27. 27.Your organization has implemented role-based access control (RBAC) to manage access to sensitive data. As...
  28. 28.Your organization is implementing a new role-based access control (RBAC) system to manage user access to...
  29. 29.A company has implemented a new access management policy that requires employees to use their company-issued...
  30. 30.You are a security technician tasked with configuring access management for a company's newly implemented...
  31. 31.A company is implementing a new wireless network and wants to ensure secure user authentication while...
  32. 32.A company is implementing a new remote access solution that requires strict user authentication and secure...
  33. 33.Your organization has implemented a RADIUS server to centralize authentication, authorization, and accounting...
  34. 34.A company has implemented a RADIUS server to centralize authentication for its network devices. To enhance...
  35. 35.An organization uses a RADIUS server to manage network access for its employees. The security team has...
  36. 36.You are tasked with securing sensitive customer data being transmitted between your company's web application...
  37. 37.A company is implementing an encrypted communication channel between its remote employees and the office...
  38. 38.A company's IT team is setting up secure communication between its internal servers and remote offices over...
  39. 39.A company's IT team is implementing encryption to secure data transmitted between their internal systems and...
  40. 40.A healthcare organization needs to ensure that sensitive patient data is protected during both storage and...
  41. 41.A company wants to ensure the confidentiality of sensitive customer data stored in its database. Which...
  42. 42.An organization is planning to transmit sensitive customer data over the internet and wants to ensure it is...
  43. 43.A company is transmitting sensitive customer data over the internet. To ensure the data remains secure during...
  44. 44.A financial organization wants to transmit sensitive customer data to an external partner securely. The data...
  45. 45.A cybersecurity analyst is tasked with ensuring the security of sensitive data stored in a database. The data...
  46. 46.A company is transferring sensitive customer data between two branch offices over the internet. To ensure the...
  47. 47.A company is transferring sensitive customer data between its on-premises data center and a cloud storage...
  48. 48.A cybersecurity technician is tasked with ensuring the confidentiality of sensitive customer data as it is...
  49. 49.A company wants to ensure sensitive customer data is protected during transfers between their web application...
  50. 50.A cybersecurity analyst is tasked with ensuring sensitive customer data remains secure when it is transmitted...
  51. 51.While reviewing network logs, a cybersecurity technician notices multiple failed login attempts from the same...
  52. 52.A company’s network administrator notices unusual traffic patterns on the network. Upon investigation, they...
  53. 53.An organization has recently experienced unauthorized access to its internal network. During the...
  54. 54.A company’s network administrator notices unusual activity on the network, such as unauthorized access...
  55. 55.A company recently implemented a firewall to protect its internal network. During a routine security review,...
  56. 56.An attacker exploits a vulnerability in the TCP three-way handshake by sending a large number of SYN packets...
  57. 57.A security analyst notices unusual traffic patterns on a network and suspects a TCP SYN flood attack is...
  58. 58.During a network security assessment, a cybersecurity technician identifies that an attacker exploited a...
  59. 59.A network administrator notices a significant amount of unauthorized traffic on their network and suspects...
  60. 60.A network administrator notices unusual traffic patterns indicating that an attacker might be exploiting a...
  61. 61.A user reports that they are unable to access a specific website, but other websites load without issue. As a...
  62. 62.A network administrator is troubleshooting an issue where a host is unable to resolve domain names to IP...
  63. 63.A user reports that they are unable to access a specific website. As part of your troubleshooting, you decide...
  64. 64.A network administrator notices that a specific device in the network is unable to communicate with others...
  65. 65.A cybersecurity analyst is troubleshooting a connectivity issue between two devices on the same local...
  66. 66.A network administrator is tasked with securing a corporate network. They notice that several devices on the...
  67. 67.During a security audit of a company's network, the cybersecurity technician discovers that an internal...
  68. 68.A company has noticed unusual activity on its network. After investigation, it was discovered that attackers...
  69. 69.A company has implemented a network segmentation strategy by dividing its internal network into separate...
  70. 70.An organization is experiencing unauthorized access attempts from external IP addresses. The network...
  71. 71.You are configuring a network for a small office. The office has multiple devices that need internet access,...
  72. 72.A company has a network with the following characteristics: it uses private IP addresses within the...
  73. 73.A company is setting up a new internal network for its employees. The IT team wants to ensure that devices...
  74. 74.A company has a network with the IP range 192.168.1.0/24 but needs to divide it into smaller subnets to...
  75. 75.Your company is redesigning its network architecture to improve security and scalability. The plan involves...
  76. 76.A cybersecurity analyst is investigating unusual traffic patterns in a company's network. To identify the...
  77. 77.A cybersecurity technician is tasked with securing the network infrastructure of a small business. The...
  78. 78.A cybersecurity technician is troubleshooting a security issue involving an organization's network traffic....
  79. 79.A company is experiencing frequent network outages impacting its internal communication. As part of your...
  80. 80.A company is experiencing frequent delays in accessing internal resources hosted on their on-premises...
  81. 81.A company is deploying a web application that needs to be accessible to external users over the internet. To...
  82. 82.An organization is setting up a web application that requires secure access for external users. To minimize...
  83. 83.A company wants to host its web application securely while minimizing the risk of external threats reaching...
  84. 84.Your organization is deploying a web server that must be accessible to the public but also needs to securely...
  85. 85.A company is designing a network security architecture for its hybrid environment that includes an...
  86. 86.You have been tasked with setting up a secure wireless network for a small office/home office (SoHo). Which...
  87. 87.You are tasked with setting up a secure wireless network for a small office/home office (SoHo). Which of the...
  88. 88.A small office/home office (SoHo) user wants to set up a secure wireless network. Which of the following...
  89. 89.You are tasked with setting up a secure wireless SoHo network for a small business. Which of the following...
  90. 90.You are tasked with setting up a secure wireless network for a small office/home office (SoHo). Which of the...
  91. 91.A small business wants to secure its Wi-Fi network by allowing only specific devices to connect and ensuring...
  92. 92.A network administrator has configured a wireless network with WPA3 encryption, disabled SSID broadcasting,...
  93. 93.You are tasked with configuring a small office wireless network to enhance security. The company wants to...
  94. 94.A company is setting up a wireless network for its employees and wants to enhance its security. They decide...
  95. 95.A company’s IT administrator wants to enhance the security of their wireless network. They have implemented...
  96. 96.An organization has implemented a secure access policy for remote workers. The security team has decided to...
  97. 97.A company is transitioning to remote work and needs to ensure secure access to internal systems for employees...
  98. 98.A company's IT department is implementing secure access technologies to protect sensitive internal resources....
  99. 99.A company has implemented a secure remote access solution for its employees working from home. They want to...
  100. 100.A company has set up a remote access policy for its employees to securely access internal resources while...
  101. 101.A company has recently implemented a network security policy requiring only authorized devices to access...
  102. 102.A company wants to secure remote access for its employees while ensuring that only authorized devices can...
  103. 103.Your company has implemented a VPN for secure remote access and a firewall to monitor incoming and outgoing...
  104. 104.A company has recently experienced multiple unauthorized access attempts to its internal network. The...
  105. 105.A company has recently deployed a network access control (NAC) solution to ensure that only authorized and...
  106. 106.A company’s IT team has deployed an endpoint detection and response (EDR) solution across all employee...
  107. 107.A cybersecurity technician is tasked with securing an organization's endpoints against malware and...
  108. 108.A company has deployed endpoint detection and response (EDR) solutions across its network. During a routine...
  109. 109.A company's IT team has implemented endpoint detection and response (EDR) software on all corporate devices...
  110. 110.A company’s security team has implemented endpoint detection and response (EDR) software across all employee...
  111. 111.A cybersecurity technician is tasked with securing a company's servers running different operating systems....
  112. 112.A cybersecurity analyst at your organization has identified that several systems are missing critical...
  113. 113.A cybersecurity technician is tasked with securing the operating system of an organization's servers. As part...
  114. 114.A company's IT team has noticed an increase in malicious software infections on their systems. To mitigate...
  115. 115.A cybersecurity technician is tasked with securing a company's workstations that run various operating...
  116. 116.A cybersecurity technician discovers a suspicious process running on a Windows host. They decide to...
  117. 117.A system administrator notices unauthorized changes to a critical configuration file on a Linux server. They...
  118. 118.A system administrator notices abnormal behavior on a Windows server, such as unknown processes running and...
  119. 119.A cybersecurity technician notices unusual activity on a Windows server. There are unauthorized file...
  120. 120.A company suspects that an attacker has gained unauthorized access to a Windows server by escalating...
  121. 121.A cybersecurity analyst is tasked with assessing the security status of corporate endpoints. They need to...
  122. 122.A security analyst is tasked with assessing the security posture of multiple endpoints in a corporate...
  123. 123.A security analyst has been tasked with assessing the security posture of several company endpoints. Which...
  124. 124.A company's IT security team suspects that a malware infection occurred on an employee's workstation. Which...
  125. 125.A company suspects that one of its endpoints has been compromised by malware. As a cybersecurity technician,...
  126. 126.A network administrator suspects that a specific host is unreachable due to a DNS resolution issue. Which of...
  127. 127.You are tasked with identifying the source of network connectivity issues reported by employees in your...
  128. 128.You are a cybersecurity technician investigating a potential DNS spoofing attack on your organization’s...
  129. 129.A user reports that they are unable to access a specific website, and you suspect a DNS resolution issue....
  130. 130.A network administrator suspects that a host in the network is attempting to make suspicious outbound...
  131. 131.A company has implemented a security policy requiring all employee laptops to have up-to-date antivirus...
  132. 132.An organization has implemented a policy requiring all endpoint devices to have antivirus software installed...
  133. 133.A cybersecurity team is tasked with verifying that all endpoint systems in the organization comply with the...
  134. 134.As a cybersecurity technician, you receive an alert that a company's endpoint devices are not meeting the...
  135. 135.You are a cybersecurity technician tasked with ensuring all endpoint systems in your organization comply with...
  136. 136.An organization is implementing a Bring Your Own Device (BYOD) policy to allow employees to use their...
  137. 137.A company has implemented a Bring Your Own Device (BYOD) policy to allow employees to use personal devices...
  138. 138.A healthcare organization is implementing a Bring Your Own Device (BYOD) policy for its employees. To ensure...
  139. 139.Your organization has implemented a Bring Your Own Device (BYOD) policy. A cybersecurity audit reveals that...
  140. 140.Your organization has implemented a Bring Your Own Device (BYOD) policy, allowing employees to use personal...
  141. 141.A company has recently experienced a cybersecurity breach due to a vulnerability in their operating system....
  142. 142.A company has recently discovered a critical vulnerability in one of its enterprise applications. As a...
  143. 143.You are a junior cybersecurity technician and receive a notification about a critical vulnerability in a...
  144. 144.A cybersecurity technician is tasked with ensuring that all company endpoints are protected from known...
  145. 145.A system administrator notices that a critical security patch for a widely-used software application has been...
  146. 146.A company’s cybersecurity team has identified multiple vulnerabilities on their Windows servers due to...
  147. 147.A cybersecurity technician is tasked with ensuring that all endpoints in the organization are protected...
  148. 148.A financial services company experiences a cyberattack that exploits an unpatched vulnerability in one of its...
  149. 149.A company has recently experienced a data breach due to an exploit targeting an unpatched vulnerability in a...
  150. 150.A cybersecurity technician notices that a Windows server hosting critical applications has not been updated...
  151. 151.You are a cybersecurity technician reviewing system logs from a web server. The log contains repeated entries...
  152. 152.A cybersecurity analyst has been tasked with investigating unusual traffic on a company's network. Upon...
  153. 153.A cybersecurity technician is tasked with reviewing system logs after a suspected breach. Upon examining the...
  154. 154.You are a cybersecurity technician tasked with investigating a potential unauthorized access incident. While...
  155. 155.You are a cybersecurity technician investigating a potential security incident involving unauthorized access...
  156. 156.A cybersecurity analyst is investigating a suspected malware infection on a Windows server. They open the...
  157. 157.A company's security team suspects that a recent application crash might be the result of unauthorized access...
  158. 158.You are a cybersecurity technician investigating a potential security incident. While reviewing the Event...
  159. 159.You are a junior cybersecurity technician investigating a potential security incident in a corporate...
  160. 160.A system administrator notices unexpected activity on a server and decides to investigate using the Event...
  161. 161.A user reports that their computer is running slower than usual, and pop-ups are appearing frequently, even...
  162. 162.Your organization's antivirus software has detected a malicious file on an employee's workstation. As part of...
  163. 163.A user reports that their computer is running slowly and behaving unusually. Upon investigation, you suspect...
  164. 164.A user reports that their computer is running unusually slow, displays frequent pop-ups, and redirects them...
  165. 165.A user reports that their computer is running unusually slow, and you suspect malware might be responsible....
  166. 166.You are a cybersecurity technician tasked with investigating a potential malware infection in your...
  167. 167.A cybersecurity technician is conducting a routine scan of the organization's systems using a vulnerability...
  168. 168.You are performing a routine vulnerability scan on your organization's systems and notice a critical severity...
  169. 169.During a routine vulnerability scan, you detect unusual file activity on a critical server. The scan logs...
  170. 170.A cybersecurity technician is performing a routine vulnerability scan on a company server. The scan...
  171. 171.During a routine vulnerability assessment, a cybersecurity technician discovers a critical vulnerability in a...
  172. 172.During a routine vulnerability assessment of your organization's network, you discover that a critical server...
  173. 173.A financial institution recently conducted a vulnerability assessment and discovered a critical vulnerability...
  174. 174.A company recently conducted a vulnerability assessment and discovered a critical vulnerability in its web...
  175. 175.A small retail company recently conducted a vulnerability assessment on their network and identified a...
  176. 176.A company has recently implemented a vulnerability management program. During the first scanning cycle, the...
  177. 177.You are a junior cybersecurity technician at an organization, and your team recently conducted a...
  178. 178.You are a cybersecurity technician tasked with implementing a vulnerability management program for your...
  179. 179.A company has recently implemented a vulnerability management program. During a routine scan, the team...
  180. 180.Your organization has recently deployed a vulnerability management tool to identify and address security...
  181. 181.A cybersecurity technician is tasked with identifying vulnerabilities in a company's network. They decide to...
  182. 182.A cybersecurity analyst is tasked with identifying vulnerabilities in a company’s network without disrupting...
  183. 183.A cybersecurity analyst has been tasked with identifying vulnerabilities in an organization's network. The...
  184. 184.As a cybersecurity technician, you are tasked to assess the security posture of a client's web application...
  185. 185.During a routine security assessment, a cybersecurity technician is tasked with identifying vulnerabilities...
  186. 186.A cybersecurity analyst is reviewing threat intelligence reports and discovers that a new vulnerability has...
  187. 187.You are a cybersecurity technician tasked with identifying potential vulnerabilities in your organization's...
  188. 188.You are a cybersecurity technician analyzing potential vulnerabilities in your organization's network. During...
  189. 189.You are a junior cybersecurity technician tasked with identifying potential vulnerabilities in your...
  190. 190.You are tasked with assessing your organization's network vulnerabilities using threat intelligence...
  191. 191.A cybersecurity analyst discovers a new vulnerability in a company’s web application. To address the issue...
  192. 192.A cybersecurity team has discovered a potential vulnerability in their organization’s web application. The...
  193. 193.You are a cybersecurity technician tasked with addressing a recent vulnerability identified in your...
  194. 194.You are a cybersecurity technician at a mid-sized company. During a routine vulnerability assessment, you...
  195. 195.A cybersecurity analyst at your organization has reported a recent vulnerability identified in a widely used...
  196. 196.A cybersecurity team is tasked with implementing a risk management strategy for an organization's IT...
  197. 197.A company has identified a vulnerability in its web server that could allow attackers to perform a...
  198. 198.A company has recently identified that its internal systems are vulnerable to ransomware attacks. As part of...
  199. 199.Your organization is planning to implement a new cloud-based application. During the planning phase, the...
  200. 200.An organization is assessing its risk management strategy after a recent security audit identified multiple...
  201. 201.Your organization has identified a vulnerability in its web application that could allow attackers to perform...
  202. 202.A small business has discovered a vulnerability in their web application that allows unauthorized users to...
  203. 203.A cybersecurity analyst discovers a vulnerability in a web application that could allow an attacker to...
  204. 204.A cybersecurity analyst discovers that a web application used by the organization has a vulnerability that...
  205. 205.An organization has discovered a vulnerability in one of its web applications that could allow attackers to...
  206. 206.An organization is implementing a new cloud-based customer relationship management (CRM) system. During the...
  207. 207.You are conducting a security assessment of an IT system for a healthcare organization. During the process,...
  208. 208.During a routine security assessment, your organization identifies sensitive customer data stored in an...
  209. 209.A cybersecurity analyst is conducting a security assessment of an organization’s IT systems. During the...
  210. 210.An organization is planning to classify its data to improve security measures. During a security assessment,...
  211. 211.A company has experienced a ransomware attack that has encrypted critical customer data. The IT team is...
  212. 212.A company experiences a ransomware attack that encrypts its critical business data. Despite the attack, the...
  213. 213.Your organization recently experienced a ransomware attack that caused extended downtime for critical...
  214. 214.A company experiences a ransomware attack that disables access to critical business systems. The IT team...
  215. 215.A company recently experienced a ransomware attack that disrupted its operations for several days. As part of...
  216. 216.An organization’s data center was struck by a hurricane, causing physical damage to the infrastructure and...
  217. 217.An organization has recently experienced a ransomware attack that encrypted critical business files. The IT...
  218. 218.A financial services company is located in an area prone to both hurricanes and cyberattacks. They want to...
  219. 219.Your organization operates a cloud-based service that handles critical customer data. A recent hurricane...
  220. 220.A company has its main data center located in a region prone to hurricanes. To ensure business continuity,...
  221. 221.A company’s IT team detects unusual outbound traffic from a server in the network. As part of the incident...
  222. 222.A company's cybersecurity team detects unusual traffic from an internal server to an external IP address...
  223. 223.During a cybersecurity incident, a company's email server has been compromised, and sensitive data has been...
  224. 224.A company has detected unusual outbound traffic from a workstation, indicating a possible data exfiltration...
  225. 225.A company receives an alert indicating suspicious activity on one of its servers. The security team needs to...
  226. 226.You are monitoring security events through a Security Information and Event Management (SIEM) system and...
  227. 227.You are monitoring security events in a Security Information and Event Management (SIEM) system and notice an...
  228. 228.You are monitoring security events on your organization's network and notice a large number of failed login...
  229. 229.You are monitoring security events in your organization's SIEM (Security Information and Event Management)...
  230. 230.A cybersecurity analyst is using both a SIEM and a SOAR platform to monitor network activity. During a...
  231. 231.A cybersecurity analyst is using a Security Information and Event Management (SIEM) tool to monitor network...
  232. 232.During routine network monitoring, a security analyst observes unusual activity in the system logs and...
  233. 233.You are a cybersecurity technician monitoring network data through a company's SIEM system. The system...
  234. 234.A cybersecurity analyst is monitoring a Security Information and Event Management (SIEM) system and notices...
  235. 235.During an investigation of a suspected insider threat, a cybersecurity team is tasked with identifying the...
  236. 236.During an investigation of a security breach, a digital forensic analyst collects and examines a compromised...
  237. 237.During a cybersecurity investigation, a company’s security team is attempting to determine the source of a...
  238. 238.During a cybersecurity investigation, an analyst is tasked with identifying the source of a ransomware attack...
  239. 239.A cybersecurity team is investigating a ransomware attack on their organization. During the digital forensics...
  240. 240.During an investigation of a suspected ransomware attack, a cybersecurity analyst uses the MITRE ATT&CK...
  241. 241.An organization’s security team has detected unusual network activity indicating a possible intrusion. They...
  242. 242.A cybersecurity analyst is investigating a potential data breach at an organization. They are tasked with...
  243. 243.A security analyst is investigating a potential breach of a company's network. Using the Cyber Kill Chain...
  244. 244.A cybersecurity analyst is investigating a potential data breach at an organization. During the...
  245. 245.A cybersecurity team is responding to a data breach in an organization that processes customer credit card...
  246. 246.During an incident response process, a cybersecurity technician is asked to ensure that the organization's...
  247. 247.A cybersecurity analyst is responding to a data breach in a healthcare organization. During the...
  248. 248.A company handling sensitive customer data experiences a cybersecurity incident involving unauthorized access...
  249. 249.A cybersecurity analyst is responding to a data breach involving customer personally identifiable information...
  250. 250.A healthcare organization has experienced a data breach that exposed sensitive patient information, including...
  251. 251.A healthcare organization stores patient data on a cloud platform. During an internal audit, you discover...
  252. 252.A company that processes credit card transactions has been informed of a potential security breach involving...
  253. 253.A healthcare organization suspects a data breach involving patient records. Under which compliance framework...
  254. 254.A healthcare organization is implementing a new patient data management system. As part of the deployment,...
  255. 255.An organization experiences a ransomware attack that locks critical business files. The security team begins...
  256. 256.During a cybersecurity incident, your organization experienced a ransomware attack that encrypted critical...
  257. 257.During a cybersecurity incident, your team has detected unauthorized access to a critical database. As the...
  258. 258.During a cybersecurity incident, your organization follows a structured incident response plan. Which of the...
  259. 259.A company has detected unauthorized access to its internal database containing sensitive customer...
  260. 260.An organization experiences a ransomware attack that encrypts critical business data. The incident response...
  261. 261.Your organization has recently experienced a malware attack that compromised several endpoints. As part of...
  262. 262.Your organization recently experienced a ransomware attack. As part of the incident response, the security...
  263. 263.Your organization recently experienced a ransomware attack, and you have been asked to assist in the incident...
  264. 264.Your organization has detected unusual traffic that may indicate a cybersecurity incident. According to the...
  265. 265.

100-160 exam dumps FAQ

Are these 100-160 dumps real exam questions?

No. These are original practice questions written to the Cisco Certified Support Technician (CCST) Cybersecurity exam objectives, not questions copied from a live exam. Memorising leaked questions violates Cisco's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many 100-160 practice questions are there?

265 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the 100-160 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed 100-160 practice test?

Sign in and start the Cisco Certified Support Technician (CCST) Cybersecurity exam on HydraNode. A session gives you 75 questions drawn from this bank in 120 minutes, then a score report with a per-question review.