100-160 exam dumps

100-160 practice question 20 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 20

Select 3

An employee in your organization clicks on a link in a phishing email, which downloads malware onto their computer. The malware spreads laterally across the network, encrypting critical data and demanding payment for recovery. Which common threats and vulnerabilities contributed to this scenario?

  1. A

    Social engineering attack targeting human vulnerabilities

  2. B

    Unpatched software enabling the malware to exploit known vulnerabilities

  3. C

    Misconfigured firewalls allowing unauthorized lateral movement

  4. D

    Weak physical security controls at the data center

  5. E

    Poor password hygiene leading to credential compromise

Show answer and explanation

Correct answers: A, B, C

Explanation

This scenario highlights multiple common threats and vulnerabilities. Social engineering (phishing) exploits human behavior to initiate the attack. Additionally, unpatched software and misconfigured firewalls create technical vulnerabilities that allow malware to spread across the network. Understanding these threats is essential for mitigating risks and protecting organizational assets.

  • A. Correct.

    Social engineering, such as phishing, is a common technique used to exploit human vulnerabilities and trick employees into downloading malware.

  • B. Correct.

    Unpatched software often contains known vulnerabilities that attackers can exploit to spread malware or gain unauthorized access.

  • C. Correct.

    Misconfigured firewalls can fail to prevent unauthorized lateral movement, allowing the malware to spread across the network.

  • D. Incorrect.

    While weak physical security controls are a concern, they are not directly relevant to the described scenario involving phishing and malware spreading digitally.

  • E. Incorrect.

    Poor password hygiene is not directly applicable in this case, as the scenario does not mention compromised credentials being a factor.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam