100-160 exam dumps

100-160 practice question 19 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 19

Single answer

A small company's IT administrator discovers unusual outbound traffic from one of their servers, which is also experiencing slower-than-usual performance. Upon investigation, they find that sensitive data has been exfiltrated to an unknown external IP address. Which type of threat is most likely responsible for this incident?

  1. A

    Phishing attack

  2. B

    Denial-of-Service (DoS) attack

  3. C

    Ransomware

  4. D

    Advanced Persistent Threat (APT)

Show answer and explanation

Correct answer: D

Explanation

The scenario describes a situation where an attacker has gained unauthorized access to a server, maintained persistence, and exfiltrated sensitive data. This is characteristic of an Advanced Persistent Threat (APT), which involves targeted, long-term attacks aimed at stealing sensitive information. The other options do not align with the described behavior of the threat.

  • A. Incorrect.

    A phishing attack typically involves tricking individuals into sharing sensitive information, such as login credentials, via deceptive emails or websites. While phishing could be a precursor to this scenario, it does not directly explain the ongoing exfiltration of data and server compromise described.

  • B. Incorrect.

    A Denial-of-Service (DoS) attack aims to overwhelm a system or network, rendering it unavailable to legitimate users. This does not align with the symptoms described, such as data exfiltration and slower server performance.

  • C. Incorrect.

    Ransomware encrypts files and demands payment for decryption. While it can disrupt server operations, it does not involve covert data exfiltration to an external IP address.

  • D. Correct.

    An Advanced Persistent Threat (APT) is a prolonged and targeted attack where cybercriminals infiltrate a network to steal sensitive data while remaining undetected. This matches the described situation, as the attacker has maintained access to the server and exfiltrated data to an unknown IP.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam