Cisco CCST Cybersecurity sample questions with explanations for 100-160 security principles, controls, risk, alerts, and incident handling.
These original sample questions help you practice CCST Cybersecurity decisions. They are not taken from the live Cisco exam.
A company wants to reduce the chance that a stolen password alone can access email. Which control best fits?
Best answer: A
Explanation: MFA strengthens authentication by requiring more than the password alone.
A vulnerability scan reports a medium-severity issue on an internet-facing server, and threat intelligence shows active exploitation. What should the technician consider?
Best answer: B
Explanation: Risk priority depends on context, not score alone. Exposure and active exploitation increase urgency.
Which statement best separates authentication from authorization?
Best answer: B
Explanation: Authentication answers “who are you?” Authorization answers “what may you do?”
An IDS generates an alert for traffic to a suspicious domain. What is the best first analyst habit?
Best answer: B
Explanation: An alert is a signal. Good triage validates the source, asset, timeline, and related evidence before choosing containment or escalation.
A user asks a technician to share an administrative password in chat so a task can be completed faster. What is the safest response?
Best answer: B
Explanation: Secure support behavior avoids sharing secrets and follows approved access workflows.
Which control most directly separates guest Wi-Fi users from internal systems?
Best answer: A
Explanation: Segmentation separates traffic and reduces exposure between groups such as guests and internal systems.
A laptop shows a malware alert with suspicious outbound connections. Which support action is usually safest?
Best answer: A
Explanation: Suspected malware requires controlled containment and evidence preservation, not convenience-driven bypasses.
Which term describes reducing risk when the full fix cannot be applied immediately?
Best answer: A
Explanation: Mitigation reduces risk temporarily or partially. Remediation fixes or removes the weakness.