100-160 exam dumps

100-160 practice question 25 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 25

Select 2

A company has recently experienced a ransomware attack that encrypted critical files and demanded payment in cryptocurrency. Upon investigation, it was discovered that the attacker gained access to the network through a phishing email that tricked an employee into downloading a malicious attachment. Which cybersecurity risks played a role in this attack?

  1. A

    Social engineering attack

  2. B

    Insider threat

  3. C

    Ransomware

  4. D

    Man-in-the-middle attack

  5. E

    IoT vulnerabilities

Show answer and explanation

Correct answers: A, C

Explanation

The attack involved two key elements: the use of a phishing email (a form of social engineering) to trick an employee into downloading malware, and the deployment of ransomware to encrypt files and extort payment. Understanding how different risks interact is crucial for identifying and mitigating cybersecurity threats.

  • A. Correct.

    Social engineering attack is correct because the phishing email tricked an employee into taking an action that ultimately led to the ransomware attack. Phishing is a common form of social engineering.

  • B. Incorrect.

    Insider threat is incorrect because this attack does not involve a malicious insider or an employee intentionally causing harm. The employee was unknowingly tricked, which classifies this as a social engineering attack rather than an insider threat.

  • C. Correct.

    Ransomware is correct because the attack involved malware that encrypted files and demanded a ransom, which is the definition of a ransomware attack.

  • D. Incorrect.

    Man-in-the-middle attack is incorrect because a man-in-the-middle attack involves intercepting or altering communication between two parties, which was not a factor in this scenario.

  • E. Incorrect.

    IoT vulnerabilities is incorrect because this attack did not exploit vulnerabilities in Internet of Things (IoT) devices. The vector was a phishing email and not an IoT device.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam