Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Certified Support Technician (CCST) Cybersecurity 100-160 Exam Questions

Page: 1 / 9 Total 50 questions

Want more questions? Get Premium Access.

Question 1

What should you create to prevent spoofing of the internal network?

Correct Answer: B. An ACL
Explanation:

The CCST Cybersecurity Study Guide states that Access Control Lists (ACLs) can be used to filter traffic based on IP addresses and block packets that appear to originate from the internal network but arrive from external interfaces (IP spoofing).

'ACLs can prevent spoofing by dropping traffic from external sources that claim to have an internal source address. Configuring ACLs on the perimeter firewall or router is a common countermeasure for IP spoofing.'

(CCST Cybersecurity, Basic Network Security Concepts, ACLs and Traffic Filtering section, Cisco Networking Academy)

A (NAT rule) changes IP addresses but does not inherently prevent spoofing.

B (ACL) is correct because it can enforce anti-spoofing filters.

C (host file) only affects name resolution locally.

D (DNS record) is for domain mapping, not spoofing prevention.


Question 2

A restaurant installs a second wireless router that only employees can use.

Which statement describes how to securely configure the new router?

Correct Answer: B. Configure the SSID with broadcast disabled.
Explanation:

The CCST Cybersecurity Study Guide explains that disabling SSID broadcast hides the network from casual scanning, adding a layer of obscurity. While not a complete security measure, when combined with WPA2/WPA3 encryption and strong passwords, it can help protect private wireless networks, especially in environments with separate employee and guest access.

'Disabling SSID broadcast can reduce the visibility of a wireless network, making it less likely to be detected by casual attackers. This should be combined with strong encryption and authentication.'

(CCST Cybersecurity, Basic Network Security Concepts, Wireless Security section, Cisco Networking Academy)

A (IP filtering) provides limited protection and is harder to manage for employee devices.

B is correct: Disabling SSID broadcast adds an extra layer of obscurity for the employee network.

C would make the network easier to access from outside the premises, which is less secure.

D would cause network conflicts and make segmentation impossible.


Question 3

Which two passwords follow strong password policy guidelines? (Choose 2.)

Correct Answer: A. Wh@tareyouDo1ngtoday4; D. 1mPressm3!
Explanation:

The CCST Cybersecurity course defines a strong password as one that:

Is at least 8--12 characters long

Uses a mix of uppercase, lowercase, numbers, and symbols

Avoids dictionary words, personal information, and predictable patterns

'Strong passwords combine length, complexity, and unpredictability, making them resistant to brute force and dictionary attacks.'

(CCST Cybersecurity, Essential Security Principles, Authentication and Access Control section, Cisco Networking Academy)

A is correct: It's long, mixed case, includes numbers and symbols, and is not easily guessable.

B is incorrect: It's based on a date, which is predictable.

C is incorrect: Short and based on a dictionary word.

D is correct: Uses complexity and length with leetspeak for added unpredictability.


Question 4

Which network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?

Correct Answer: A. IDS
Explanation:

The CCST Cybersecurity course states that an Intrusion Detection System (IDS) passively monitors network or system traffic and analyzes it against a database of known threat signatures or behavioral patterns.

'IDS devices inspect network traffic, compare it to known malicious signatures or anomalies, and generate alerts for suspicious activity without actively blocking traffic.'

(CCST Cybersecurity, Basic Network Security Concepts, IDS and IPS section, Cisco Networking Academy)

A is correct: IDS is passive and signature-based.

B (IPS) is active and can block traffic.

C (Proxy Server) handles requests between clients and servers.

D (Honeypot) is a decoy system to attract attackers.


Question 5

You need to design your company's password policy to adhere to the National Institute of Standards and Technology (NIST) guidelines for user password security.

What is the minimum password length that you should require to be consistent with the NIST guidelines?

Correct Answer: B. 8 characters
Explanation:

According to the CCST Cybersecurity course, NIST guidelines (SP 800-63B) recommend a minimum password length of 8 characters for user-generated passwords, without requiring overly complex composition rules, but encouraging longer passphrases for increased security.

'NIST guidelines specify that user-generated passwords must be at least 8 characters in length, and systems should allow passwords up to at least 64 characters.'

(CCST Cybersecurity, Essential Security Principles, Authentication Best Practices section, Cisco Networking Academy)


Question 6

Which encryption type is commonly used to secure WiFi networks?

Correct Answer: C. Advanced Encryption Algorithm (AES)
Explanation:

The CCST Cybersecurity Study Guide specifies that AES (Advanced Encryption Standard) is the encryption method used in modern WiFi security protocols like WPA2 and WPA3.

'WPA2 and WPA3 use the Advanced Encryption Standard (AES) for securing wireless traffic. AES provides strong symmetric encryption, replacing outdated methods like WEP and TKIP.'

(CCST Cybersecurity, Basic Network Security Concepts, Wireless Security section, Cisco Networking Academy)

A (DES) is outdated and insecure.

B (Triple DES) is older and slower, rarely used in WiFi.

C is correct: AES is the industry standard for WiFi security.

D (RSA) is asymmetric encryption used in key exchange, not bulk WiFi encryption.