100-160 exam dumps

100-160 practice question 18 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 18

Select 3

A small business has recently experienced a ransomware attack that encrypted all its critical files. Upon investigation, it was discovered that an employee unknowingly clicked on a malicious link in a phishing email. Which of the following common threats and vulnerabilities contributed to this attack?

  1. A

    Social engineering tactics used to trick the employee into clicking the link

  2. B

    Outdated antivirus software on the employee's workstation

  3. C

    Weak password policies across the organization's systems

  4. D

    Unpatched software vulnerabilities in the company's file server

  5. E

    The use of strong encryption for the ransomware payload

Show answer and explanation

Correct answers: A, B, D

Explanation

The ransomware attack was successful due to a combination of social engineering (phishing email), outdated antivirus software that failed to detect the threat, and unpatched software vulnerabilities. These are common threats and vulnerabilities that organizations must address to prevent such incidents.

  • A. Correct.

    Social engineering is a key tactic in phishing attacks where attackers manipulate individuals into performing actions such as clicking malicious links.

  • B. Correct.

    Outdated antivirus software may fail to detect or block new ransomware variants, leaving the system vulnerable to attacks.

  • C. Incorrect.

    While weak password policies are a security vulnerability, they are unrelated to how this specific ransomware attack occurred.

  • D. Correct.

    Unpatched software vulnerabilities can be exploited by attackers to deliver ransomware payloads or gain access to critical systems.

  • E. Incorrect.

    Strong encryption is a characteristic of the ransomware itself and not a vulnerability or threat that led to the attack. It describes the attack’s impact rather than its cause.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam