100-160 exam dumps

100-160 practice question 183 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 183

Single answer

A cybersecurity analyst has been tasked with identifying vulnerabilities in an organization's network. The analyst uses a tool to actively probe the network to identify open ports and services running on various devices. What type of activity is this, and which tools are typically used for such tasks?

  1. A

    Passive reconnaissance using tools like Wireshark

  2. B

    Active reconnaissance using tools like Nmap

  3. C

    Vulnerability mitigation using tools like Nessus

  4. D

    Network hardening using tools like Firewalls

Show answer and explanation

Correct answer: B

Explanation

Active reconnaissance is a method of directly interacting with a network to gather information about open ports, services, and potential vulnerabilities. Tools like Nmap are specifically designed for this purpose, making it the correct choice. Passive reconnaissance, on the other hand, involves gathering information without engaging directly with the target system, and tools like Nessus or firewalls are used for different phases in the cybersecurity lifecycle.

  • A. Incorrect.

    Passive reconnaissance involves gathering information without directly interacting with the target system. Wireshark is a packet analysis tool used for monitoring network traffic, not for probing open ports.

  • B. Correct.

    Active reconnaissance involves directly interacting with the target system to gather information, such as open ports and running services. Nmap is a commonly used tool for this purpose, making this the correct answer.

  • C. Incorrect.

    Vulnerability mitigation refers to addressing and fixing identified vulnerabilities, often after discovery. Nessus is a vulnerability assessment tool but is not used for active reconnaissance.

  • D. Incorrect.

    Network hardening involves implementing security measures like firewalls to protect the network. This is a defensive action, not reconnaissance or testing.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam