Browse all practice questions for the CCST Cybersecurity Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CCST Cybersecurity Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which description best matches the grep command?
  • Which command pair obtains a new IP address from a DHCP server?
  • Which PKI component is responsible for issuing and managing digital certificates?
  • Which statement best describes a DDoS attack?
  • In the Security Onion architecture, which tool is known as a network traffic analysis tool?
  • Under CFAA, which access is criminal?
  • Remote Desktop Protocol uses which port for typical connections?
  • What is the purpose of a DNS sinkhole in security?
  • A password cracker is software that repeatedly makes guesses in order to crack the password.
  • OpenVPN is used to provide encrypted tunneling for VPNs. Which of the following options reflects this role?
  • Which DNS record is used to publish a policy that combines SPF and DKIM results to handle unauthenticated emails?
  • What is the IPv4 address 127.0.0.1 commonly known as?
  • During which phase of the incident response process is evidence most likely gathered to support legal action?
  • What is the correct order of the four steps of Incident Response?
  • Which phase of incident response involves containment, eradication, and recovery?
  • In the SOC's three-tier model, who is Tier 3?
  • The procedure of developing controls as vulnerabilities are discovered to prevent exploitation is known as
  • What does an A record map?
  • Which technology enables accurate timestamping of network events by synchronizing time across devices?
  • Which item is NOT a listed type of cyber threat?
  • What is obfuscation in security coding?
  • Which threat type arises from the actions of people, not machines?
  • Which concept allows using the same credentials to access multiple networks or websites across different organizations, often via a single sign-on?
  • Which type of firewall works at all layers of the OSI model?
  • Which item is a type of cyber threat involving errors in software causing vulnerabilities?
  • Which set of fields constitutes the five-tuple used in network monitoring?
  • The chmod command is used to
  • Which policy change would prevent unsecured remote access?
  • What is the recommended network design to minimize risk from IoT devices with internet access?
  • What is GFI LANguard?
  • Which term describes any device that controls or filters traffic going in or out of the network?
  • In incident response, what is the primary goal of Seizure?
  • What is hardening in cybersecurity?
  • Which of the following is a packet sniffing tool?
  • Which statement best describes netstat?
  • A loopback address is an IP address that indicates your own computer and is used to test TCP/IP configuration on the computer.
  • Which Cisco product is described as an all-in-one web gateway and can block hidden malware from suspicious and legitimate websites?
  • Which command is used to display the IP routing table on Windows hosts?
  • Which of the following is a packet sniffing tool listed among the material's examples?
  • In the Diamond Model, which element represents the means by which the attacker can inflict harm (tools, techniques, and capabilities)?
  • Which DNS record is used to specify the mail server for a domain?
  • Which Exploitability criterion expresses the presence or absence of a user interaction requirement?
  • Which statement best describes Snort?
  • Which statement best describes PhishSigs as a resource?
  • NetBIOS is associated with which port range?
  • Describe HIPAA.
  • What are the two important components of a PKI used in network security?
  • Which firewall filters web content requests such as URLs and domain names?
  • Which protocols operate on the Application layer of the TCP/IP model?
  • Which option correctly names the ARP command?
  • Rootkit detectors are best described as what?
  • What class of IP addresses is used for multicast addressing?
  • What is the default number of lines displayed by the head command?
  • A sandbox in cybersecurity is best described as...
  • Which destination IPv4 address does a DHCPv4 client use to send the initial DHCP Discover packet when searching for a server?
  • Which option correctly describes the arp command's purpose?
  • TCP port 143 is used by which protocol?
  • Which policy action is appropriate when an employee leaves the company?
  • Which type of cipher encrypts plaintext one byte or one bit at a time?
  • The three open ports 22, 443, and 1521 are commonly associated with which combination of services?
  • What does ipconfig /renew do?
  • Which Act focuses on protecting consumer financial information and requires financial institutions to explain their privacy practices?
  • Which type of security system provides real-time reporting and long-term analysis of security events in an enterprise?
  • Which statement best describes camouflage in security coding techniques?
  • Which SDLC model uses linear development concepts in an iterative, four-phase process?
  • Which of the following statements correctly describes ipconfig on Windows?
  • OpenVPN is listed as an encryption tool used for what purpose?
  • Which technology creates a security token that allows a user to log into a web application using credentials from a social media website?
  • Which of the following is a technical control to support secure teleworker access to the corporate network?
  • NetFlow data is commonly used to collect and analyze traffic flow data. Which option describes this use?
  • TCP port 21 is used by:
  • Which of the following is an encryption tool?
  • What does a TXT DNS record typically store?
  • What does MTBF measure?
  • When was COPPA passed by Congress?
  • What is Nessus?
  • Which TCP/IP application layer protocol is commonly used to transfer files between a client and a server?
  • Which security coding technique is described as replacing sensitive data with realistic fictional data?
  • For what purpose would a network administrator use the Nmap tool?
  • Which command can display the NetBIOS over TCP/IP connection data?
  • Which protocol is used to send error messages and is commonly used with ping to test connectivity?
  • Which item can be managed through Group Policy (GPO) in Windows environments?
  • In incident response, Analysis is defined as
  • Which threat category involves events like floods, earthquakes that disrupt operations?
  • Cisco Advanced Malware Protection (AMP) provides which of the following?
  • Which term describes networks of compromised computers controlled by an attacker?
  • Which DNS record would an email server query to locate the destination mail server for a domain?
  • What best defines the Internet of Things (IoT)?
  • Which threat category involves stealing physical or data assets?
  • In the TCP/IP conceptual model, which layer is the lowest (closest to the physical medium)?
  • Which tool is a password auditing and recovery application?
  • What is ping command used for?
  • Which of the following best describes an Endpoint Security Suite?
  • What names are given to a database where all cryptocurrency transactions are recorded?
  • Which of the following is an example of a network scanning tool?
  • What does ARP stand for?
  • What does input validation involve in security coding techniques?
  • Which security mitigation technique involves rotating personnel roles every few months?
  • Which tool would you use to visualize the path taken by packets to a destination, showing each intermediate router (hop)?
  • TCP port 1701 is used by which VPN protocol?
  • Which agency administers COPPA?
  • Microsoft SQL Server typically listens on which port range for database connections?
  • In the OSI model, which layer is responsible for end-to-end communication control?
  • Which tool is a packet sniffer?
  • Which of the following is a recognized threat source type?
  • What information is typically required to manually connect a mobile device to a secured wireless network?
  • Which DNS record is commonly used to publish DKIM public keys?
  • Which tool is commonly used to crack wireless networks?
  • In the SOC three-tier model, which role is assigned to Tier 1?
  • What are Yara Rules used for?
  • Which is a capability area in the National Cybersecurity Workforce Framework?
  • Which SDLC model is described as repeating four phases (requirements gathering, design, build, evaluation)?
  • Which type of evidence is traditionally considered the strongest in investigations?
  • Nbstat is a utility that
  • UDP port 67 is used by?
  • Which of the following is an example of a password cracking tool?
  • What is the IPv4 multicast address range?
  • What does the MIME standard define?
  • Which protocol uses TCP port 3389 and UDP port 3389 for remote desktop connections?
  • What does ipconfig /release do?
  • What is the effect of ipconfig /renew?
  • During the deployment phase of an asset's lifecycle, what happens to the asset?
  • What is the best approach to prevent a compromised IoT device from maliciously accessing data and devices on a local network?
  • Which of the following is an example of a wireless cracking tool?
  • What should be checked first when a laptop connects to a public Wi‑Fi network?
  • CNAME records are primarily used to?
  • Which protocol operates at the Transport layer of the TCP/IP model?
  • Which of the following is a threat source type?
  • What is a Denial-of-Service (DoS) attack?
  • Which of the following protocols use the Advanced Encryption Standard (AES)?
  • Which of the following is NOT a password cracking tool?
  • Which term is a defense in depth strategy?
  • Which of the following is primarily a database of phishing-related indicators?
  • Which tool can perform real-time traffic and port analysis, and can also detect port scans, fingerprinting and buffer overflow attacks?
  • COPPA protects privacy of children under what age?
  • Which policy ensures that passwords are not reused across different applications?
  • Defense-in-Depth/Layered Security is best described as?
  • Knowingly accessing any computer used in or affecting interstate or foreign commerce without permission is a CFAA violation.
  • MS-SQL uses which port(s)?
  • What is the purpose of vulnerability scanners?
  • What type of system is designed to mislead attackers and collect information about attack methods?
  • IPv6 link-local addresses begin with which prefix?
  • Which of the following is NOT a private IPv4 address range?
  • If a SOC has a goal of 99.999% uptime, approximately how many minutes of downtime per year is considered within its goal?
  • What is the role of DNS?
  • Which tool is used to probe and test a firewall's robustness using specially crafted forged packets?
  • Which practice is essential for preventing common web application attacks like SQL Injection and XSS by validating input and using whitelists?
  • MTTC refers to the average time between the start and resolution of an incident (sometimes called MTTR for mean-time-to-resolve).
  • Which of the following is NOT listed as a recovery-control example?
  • TCP port 443 is assigned to which protocol?
  • What does the onion analogy in cybersecurity primarily illustrate?
  • Which type of message is sent to all hosts on a remote network?
  • Cisco Web Security Appliance (WSA) is best described as?
  • Which activity is associated with monitoring and investigation in security operations?
  • Which of the following is a network scanning tool?
  • In defense in depth, which term represents the idea of providing multiple overlapping protections?
  • Which device is primarily used to enforce access control by filtering traffic at a network boundary?
  • Which action should an organization take to improve wireless security?
  • Which technology protects the integrity of data in transit?
  • FTK Imager is a forensic tool that can
  • Which criterion in Exploitability reflects the level of access required for a successful exploit?
  • Which logs are most likely to reveal the IP address and MAC address of devices on the local network?
  • Which phase focuses on preparation and prevention to minimize security incidents?
  • Which components are typically included in Internet of Things deployments?
  • Which policy changes would help prevent passwords from being cracked within six hours?
  • In exploitability metrics, which criterion describes whether multiple authorities must be involved in an exploit?
  • Which statement best describes End Point Detection and Response (EDR)?
  • Which of the following is a private IPv4 address block within the 172 range?
  • The logger command is a Linux utility that
  • Which of the following is a packet crafting tool?
  • What is an advantage for small organizations of adopting IMAP instead of POP?
  • Which log type is described as a comma-delimited text file containing entries with fields such as ID, Date, Time, Description, IP Address, Host Name, and MAC Address?
  • Which techniques can be used to enhance database security?
  • Which tool is commonly used to discover hosts and services on a network as part of a pentest?
  • Which protocol is commonly used to monitor and manage network devices and can reset passwords or change device baselines?
  • Which of the following is a type of cyber threat?
  • At which layer of the TCP/IP model do devices such as switches operate, along with PPP and ARP?
  • Which threat category involves interruptions to power, water, or network connectivity?
  • Which is an example of an on-path attack that can affect mobile devices?
  • Which of the following is an encryption tool?
  • Why should an organization conform to a standard data governance framework?
  • Which KPI metric does SOAR use to measure the average time that it takes to stop and remediate a security incident?
  • Which statement correctly describes the difference between ping and traceroute?
  • Which statement best describes defense in depth?
  • What is Sguil used for?
  • Which sequence correctly lists the OSI layers from the lowest to the highest?
  • Which option correctly identifies the two tools that can detect anomalous behavior, command and control traffic, and infected hosts when used together?
  • What term is used to record the order of evidence handling, by whom, and the nature of the handling?
  • Which policy change best prevents unauthorized escalation of privileges?
  • A synchronized surge of traffic from multiple sources intended to overwhelm a target is best described as what?
  • Which protocol uses UDP port 69 for simple file transfer without authentication?
  • What does CIPA require for federal funding?
  • What does ping -t do?
  • TCP port 23 is used by:
  • Which aspect includes network infrastructure, endpoints, servers, identity management, vulnerability management, monitoring and logging?
  • What is a canary trap used for?
  • What is DKIM used for?
  • Which criterion expresses whether multiple authorities must be involved in an exploit?
  • Who typically uses Registered Ports?
  • What is Cuckoo Sandbox?
  • In the SOC's three-tier model, who is Tier 2?
  • Which artifact is used to revoke certificates and inform entities of invalid certificates?
  • TCP ports 137-139 are used by which service?
  • NetFlow provides information that helps security teams analyze traffic patterns. Which description best captures NetFlow's purpose?
  • Which secure media disposition method renders data unrecoverable to permit reuse within the organization?
  • What policy change would ensure servers are updated with the latest patches at regular intervals?
  • Which authentication protocol is well suited to untrusted networks and encrypts authentication traffic by default?
  • Which tool is described as an open source malware analysis tool that can run locally on the network?
  • What is a difference between symmetric and asymmetric encryption algorithms?
  • What does SPF primarily verify?
  • In which document would a statement like 'Windows workstations must have the current security configuration template applied before deployment' most likely belong?
  • How often should patches be updated and tested?
  • Which statement best describes the Computer Fraud and Abuse Act (CFAA) of 1986?
  • What is IMPACT in cybersecurity?
  • Mean Time to Repair (MTTR) measures?
  • Which organization ensures PCI DSS requirements are enforced for merchants and service providers?
  • NetFlow is best described as what?
  • Which statement best describes the function of a protocol analyzer?
  • Which statement about port 53 is true?
  • Standards provide mandatory requirements for how policies are carried out. Which option best describes this concept?
  • Which of the following is NOT a standard Windows event severity level?
  • Which tool is used for real-time traffic analysis and can detect port scans, fingerprinting and buffer overflow attacks?
  • Which layer focuses on securing data as it moves across networks?
  • A host is transmitting a broadcast, which hosts will receive it?
  • Which statement about ping options -6 and -4 is true?
  • TCP port 25 is used by?
  • What does MTTD stand for and measure?
  • Which statement best describes a DNS attack?
  • A software company uses a public cloud service for hosting software development and deployment services. The company is concerned that software code in development might leak to competitors and result in the loss of intellectual property. Which security coding techniques can the company implement to address the concern?
  • Which range is the loopback address range for IPv4?
  • Why does IoT technology pose a greater risk on a network?
  • NMAP is an example of which category of security tools?
  • What is the default number of lines displayed by the tail command?
  • What is used by PKI entities to verify the validity of a digital certificate?
  • UDP port 68 is used by which protocol's client service?
  • Which security policy would address the process of updating AP configurations?
  • Which tool provides a list of open ports on network devices?
  • TheHarvester is listed as which category of security tools?
  • Which job would require verification that an alert represents a true security incident or a false positive?
  • To protect intellectual property in development hosted on a public cloud, which practice is recommended?
  • Which security coding technique ensures that data displayed to users will not execute unintended code in the browser?
  • Which term describes a more complex decoy system used mainly by research, military, and government organizations?
  • The Gramm-Leach-Bliley Act (GLBA) primarily governs privacy and protection of what type of information?
  • In network security, Sniffing refers to what activity?
  • In a penetration test, the initial phase focuses on documenting the target's current state to learn as much as possible.
  • Which protocol runs over port 22 as a subsystem?
  • Which TCP/IP layer is responsible for routing packets between networks?
  • Which technology creates a security token that allows a user to log in to a desired web application using credentials from a social media website?
  • Which DNS record type is commonly used to publish security-related information such as DKIM keys and DMARC policies?
  • Which IR phase involves extracting digital contents from a seized device so they may be analyzed?
  • Which statement best describes the function of a protocol analyzer?
  • Which protocol is used to access email on servers and keep content on the server, enabling access from multiple devices?
  • Nessus is listed as which type of tool?
  • In incident response, Acquisition is best described as
  • Which three protocols are commonly used for email retrieval and sending?
  • Which firewall filters traffic based on the user, device, role, application, and threat profile?
  • What does the -a option of ping do?
  • Which stage of the kill chain used by attackers focuses on the identification and selection of targets?
  • DNS uses which port and transport protocols?
  • In the five-tuple description, which elements are included?
  • Hashing is used to generate a fixed-size digest that can be used to verify data integrity.
  • Which threat category involves issues with physical components or devices?
  • What is a production honeypot primarily used for?
  • Which tool is commonly used to scan systems for software vulnerabilities?
  • Which command is used to view the NetBIOS name cache?
  • In base metrics for exploitability, which description matches attack complexity?
  • Which action would violate the CFAA?
  • What is the primary use of a loopback address in testing network software?
  • Which protocol maps IP addresses to MAC addresses on a local network?
  • Which DNS record indicates the DNS servers assigned to a zone?
  • Which method of wireless authentication can take advantage of identity verification using a Radius server?
  • Which service commonly runs on port 22?
  • Which of the following is NOT one of the three detection tools mentioned for collecting alert data in Security Onion architecture?
  • What is the most common goal of SEO poisoning?
  • What does ping -6 do?
  • Which range defines Well Known Ports?
  • Which category includes policies, procedures, standards, user education, incident response, disaster recovery, compliance and physical security?
  • What does PCI DSS stand for and what is its focus?
  • Which type of security control focuses on people and processes rather than technology?
  • Which statement best defines an IP address spoofing attack?
  • In incident response, what is the primary goal of the Recovery phase?
  • Which statement best describes tracert/traceroute?
  • FERPA was enacted in which year?
  • Which command is commonly used to troubleshoot domain name servers and retrieve DNS resource records?
  • What is the general purpose of encryption tools as described?
  • The cat command is used to
  • What best describes a Man-in-the-Middle (MitM) attack?
  • The Electronic Communications Privacy Act (ECPA) aims to protect what?
  • COPPA took effect in April 2000.
  • What is Tripwire in IT security?
  • Which address class corresponds to experimental addresses?
  • Which DNS record maps one domain to another as an alias?
  • In incident response, Reporting is defined as
  • What is L0phtcrack?
  • Which statement best describes the security onion analogy for defense in depth?
  • What is the main function of the Cisco Security Incident Response Team?
  • What is the Nmap utility used for?
  • What is Nslookup commonly used for?
  • Using the Common Vulnerability Scoring System, which score indicates the most critical vulnerability?
  • Which protocols operate at the Network Access layer of the TCP/IP model?
  • Which statement best describes a Context Aware Application Firewall?
  • What are the four steps of Incident Response?
  • Which policy change would prevent the continued use of weak wireless encryption such as WEP?
  • Which of the following is the OpenBSD Packet Filter?
  • What type of system is used to contain an attacker to allow them to be monitored?
  • Which tool provides a console to view alerts generated by network security monitoring tools?
  • Which Cisco solution provides protection before, during, and after an attack?
  • What is another term for the internet-facing port on a wireless router?
  • The route command can
  • What is DHCP's role in a network?
  • TCP port 110 is used by which protocol?
  • Email privacy risk: Including which type of information would most likely compromise patient privacy?
  • Which debugging security tool can be used by black hats to reverse engineer binary files when writing exploits?
  • Which phase involves documenting the incident, assessing impact, and identifying improvements to prevent recurrence?
  • What is a SIEM system used for?
  • What is the Sarbanes-Oxley Act primarily concerned with?
  • In FTK Imager, which mechanism is used to verify the integrity of the acquired data?
  • What best describes a botnet?
  • What is the National Vulnerability Database (NVD)?
  • What does DMARC rely on to verify emails?
  • TCP port 80 is assigned to which protocol?
  • The HTTP status code 200 indicates what about the client request?
  • Which range is used for dynamic/private (ephemeral) ports?
  • Which option names a firewall component associated with OpenBSD Packet Filter?
  • A cyberanalyst is looking for an open source malware analysis tool that can run locally on the network. Which tool would meet the needs of the cyberanalyst?
  • What parameter identifies the application when a client requests a service from a remote server?
  • The default DHCP configuration on a home wireless router assigns which type of addresses to devices?
  • Which IR phase results in the formal written documentation?
  • In the Diamond Model, which four elements constitute its framework?
  • In a penetration test, which phase focuses on gathering information about the target network or device?
  • Which protocol is used by the Cisco Cyber Threat Defense Solution to collect information about the traffic that traverses the network?
  • Which of the following is the IPv4 link-local address range?
  • Which option does NOT align with the defense-in-depth approach?
  • Which term describes an attack that uses a network of compromised devices to flood a target's resources?
  • How many layers are in the OSI Reference Model?
  • UDP port 69 is used by which protocol?
  • What is the primary purpose of a packet analyzer?
  • Which is an on-path attack example?
  • In the cybersecurity onion model, which is the first layer to protect?
  • In exploitability metrics, which criterion expresses whether the attack requires the involvement of multiple authorities?
  • What does ping -4 do?
  • Which Cisco service provides information about security incident detection rule sets for tools such as Snort, ClamAV, and SpamCop?
  • Which tool detects vulnerabilities on networks?
  • Which remote access method is considered secure according to policy?
  • UDP ports 161/162 are used by which protocol?
  • What is the Cisco Email Security Appliance (ESA) designed to do?
  • Which is the highest layer of the OSI model?
  • TCP port 20 is used by:
  • Which act provides public access to federal agency records, subject to exemptions?
  • Which term describes segments of unused network space that are monitored to detect unauthorized traffic?
  • What is the purpose of output encoding in security coding techniques?
  • Which online sandbox is described as offering interactive reporting and the ability to upload multiple malware samples?
  • Which term describes deliberate actions to damage an organization's operations?
  • What is a feature of the ANY.RUN malware sandbox?
  • Which range defines Registered Ports?
  • The ping utility is commonly used to test what aspects of a network connection?
  • Which item is NOT typically included in an Endpoint Security Suite?
  • Which KPI metric does SOAR use to measure the time required to stop the spread of malware in the network?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy