Browse all practice questions for the CCST Cybersecurity Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CCST Cybersecurity Practice Test 2026 - Free Cybersecurity Exam Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • During the deployment phase of an asset's lifecycle, what happens to the asset?
  • What best defines the Internet of Things (IoT)?
  • To protect intellectual property in development hosted on a public cloud, which practice is recommended?
  • Which TCP/IP application layer protocol is commonly used to transfer files between a client and a server?
  • Which item is NOT typically included in an Endpoint Security Suite?
  • The procedure of developing controls as vulnerabilities are discovered to prevent exploitation is known as
  • Which policy action is appropriate when an employee leaves the company?
  • In defense in depth, which term represents the idea of providing multiple overlapping protections?
  • Which DNS record maps one domain to another as an alias?
  • Which tool is described as an open source malware analysis tool that can run locally on the network?
  • Which of the following is an encryption tool?
  • Cisco Advanced Malware Protection (AMP) provides which of the following?
  • Which statement best describes End Point Detection and Response (EDR)?
  • What does CIPA require for federal funding?
  • What is a Denial-of-Service (DoS) attack?
  • Which statement best describes a DDoS attack?
  • What term is used to record the order of evidence handling, by whom, and the nature of the handling?
  • Which statement correctly describes the difference between ping and traceroute?
  • In the Diamond Model, which four elements constitute its framework?
  • Nbstat is a utility that
  • Which action should an organization take to improve wireless security?
  • In FTK Imager, which mechanism is used to verify the integrity of the acquired data?
  • In the SOC's three-tier model, who is Tier 2?
  • Which threat category involves stealing physical or data assets?
  • Which destination IPv4 address does a DHCPv4 client use to send the initial DHCP Discover packet when searching for a server?
  • Which phase focuses on preparation and prevention to minimize security incidents?
  • FERPA was enacted in which year?
  • What is the general purpose of encryption tools as described?
  • Which statement best describes the function of a protocol analyzer?
  • Which policy change would prevent the continued use of weak wireless encryption such as WEP?
  • What is a production honeypot primarily used for?
  • Which action would violate the CFAA?
  • Which organization ensures PCI DSS requirements are enforced for merchants and service providers?
  • DNS uses which port and transport protocols?
  • Which techniques can be used to enhance database security?
  • Which act provides public access to federal agency records, subject to exemptions?
  • Which KPI metric does SOAR use to measure the time required to stop the spread of malware in the network?
  • Which statement best describes camouflage in security coding techniques?
  • Which range is the loopback address range for IPv4?
  • Which SDLC model is described as repeating four phases (requirements gathering, design, build, evaluation)?
  • During which phase of the incident response process is evidence most likely gathered to support legal action?
  • Which statement best describes the Computer Fraud and Abuse Act (CFAA) of 1986?
  • Which tool is commonly used to crack wireless networks?
  • In incident response, what is the primary goal of Seizure?
  • Using the Common Vulnerability Scoring System, which score indicates the most critical vulnerability?
  • Nessus is listed as which type of tool?
  • What is the purpose of a DNS sinkhole in security?
  • What best describes a Man-in-the-Middle (MitM) attack?
  • In a penetration test, the initial phase focuses on documenting the target's current state to learn as much as possible.
  • Which address class corresponds to experimental addresses?
  • Which remote access method is considered secure according to policy?
  • Which protocol is used to send error messages and is commonly used with ping to test connectivity?
  • What is the correct order of the four steps of Incident Response?
  • Which statement best describes the function of a protocol analyzer?
  • What is the Cisco Email Security Appliance (ESA) designed to do?
  • Which tool is used for real-time traffic analysis and can detect port scans, fingerprinting and buffer overflow attacks?
  • Which of the following statements correctly describes ipconfig on Windows?
  • What is a canary trap used for?
  • Which of the following is the IPv4 link-local address range?
  • Which tool provides a list of open ports on network devices?
  • In the five-tuple description, which elements are included?
  • Cisco Web Security Appliance (WSA) is best described as?
  • Which statement best describes PhishSigs as a resource?
  • A password cracker is software that repeatedly makes guesses in order to crack the password.
  • Which of the following is a private IPv4 address block within the 172 range?
  • What is the recommended network design to minimize risk from IoT devices with internet access?
  • Which service commonly runs on port 22?
  • Which tool is commonly used to scan systems for software vulnerabilities?
  • Which technology creates a security token that allows a user to log in to a desired web application using credentials from a social media website?
  • Which KPI metric does SOAR use to measure the average time that it takes to stop and remediate a security incident?
  • TCP port 110 is used by which protocol?
  • TCP port 21 is used by:
  • What is the IPv4 address 127.0.0.1 commonly known as?
  • Which threat category involves issues with physical components or devices?
  • Which PKI component is responsible for issuing and managing digital certificates?
  • At which layer of the TCP/IP model do devices such as switches operate, along with PPP and ARP?
  • Which term describes networks of compromised computers controlled by an attacker?
  • Which type of security control focuses on people and processes rather than technology?
  • What are the two important components of a PKI used in network security?
  • What is the purpose of vulnerability scanners?
  • What is a SIEM system used for?
  • Which term describes deliberate actions to damage an organization's operations?
  • Which criterion expresses whether multiple authorities must be involved in an exploit?
  • Which range defines Registered Ports?
  • In incident response, Analysis is defined as
  • Which DNS record indicates the DNS servers assigned to a zone?
  • Knowingly accessing any computer used in or affecting interstate or foreign commerce without permission is a CFAA violation.
  • Which security coding technique is described as replacing sensitive data with realistic fictional data?
  • Which log type is described as a comma-delimited text file containing entries with fields such as ID, Date, Time, Description, IP Address, Host Name, and MAC Address?
  • Which type of cipher encrypts plaintext one byte or one bit at a time?
  • Mean Time to Repair (MTTR) measures?
  • Which of the following is NOT listed as a recovery-control example?
  • A software company uses a public cloud service for hosting software development and deployment services. The company is concerned that software code in development might leak to competitors and result in the loss of intellectual property. Which security coding techniques can the company implement to address the concern?
  • IPv6 link-local addresses begin with which prefix?
  • COPPA took effect in April 2000.
  • The HTTP status code 200 indicates what about the client request?
  • The Gramm-Leach-Bliley Act (GLBA) primarily governs privacy and protection of what type of information?
  • What is the primary purpose of a packet analyzer?
  • Which of the following is a technical control to support secure teleworker access to the corporate network?
  • Which DNS record would an email server query to locate the destination mail server for a domain?
  • Which tool is a packet sniffer?
  • TCP port 25 is used by?
  • Which SDLC model uses linear development concepts in an iterative, four-phase process?
  • Which range defines Well Known Ports?
  • Which of the following best describes an Endpoint Security Suite?
  • What is Sguil used for?
  • Which firewall filters traffic based on the user, device, role, application, and threat profile?
  • Which of the following is a packet crafting tool?
  • Which option correctly describes the arp command's purpose?
  • Which command is used to view the NetBIOS name cache?
  • Which protocol runs over port 22 as a subsystem?
  • What is IMPACT in cybersecurity?
  • The cat command is used to
  • In incident response, what is the primary goal of the Recovery phase?
  • Which term describes an attack that uses a network of compromised devices to flood a target's resources?
  • What is the effect of ipconfig /renew?
  • Which statement best defines an IP address spoofing attack?
  • Which IR phase results in the formal written documentation?
  • What does ARP stand for?
  • Which of the following is the OpenBSD Packet Filter?
  • MTTC refers to the average time between the start and resolution of an incident (sometimes called MTTR for mean-time-to-resolve).
  • NetFlow provides information that helps security teams analyze traffic patterns. Which description best captures NetFlow's purpose?
  • What is ping command used for?
  • Which protocols operate at the Network Access layer of the TCP/IP model?
  • Which option correctly identifies the two tools that can detect anomalous behavior, command and control traffic, and infected hosts when used together?
  • TCP port 1701 is used by which VPN protocol?
  • Which of the following is an example of a password cracking tool?
  • Which policy changes would help prevent passwords from being cracked within six hours?
  • Which range is used for dynamic/private (ephemeral) ports?
  • Which of the following is an example of a network scanning tool?
  • OpenVPN is listed as an encryption tool used for what purpose?
  • Which authentication protocol is well suited to untrusted networks and encrypts authentication traffic by default?
  • What are the four steps of Incident Response?
  • Which phase of incident response involves containment, eradication, and recovery?
  • What is DKIM used for?
  • Which item is NOT a listed type of cyber threat?
  • CNAME records are primarily used to?
  • Which type of security system provides real-time reporting and long-term analysis of security events in an enterprise?
  • Which tool would you use to visualize the path taken by packets to a destination, showing each intermediate router (hop)?
  • UDP port 69 is used by which protocol?
  • Which technology enables accurate timestamping of network events by synchronizing time across devices?
  • What is the default number of lines displayed by the tail command?
  • In the Diamond Model, which element represents the means by which the attacker can inflict harm (tools, techniques, and capabilities)?
  • A cyberanalyst is looking for an open source malware analysis tool that can run locally on the network. Which tool would meet the needs of the cyberanalyst?
  • What is a feature of the ANY.RUN malware sandbox?
  • Which policy ensures that passwords are not reused across different applications?
  • If a SOC has a goal of 99.999% uptime, approximately how many minutes of downtime per year is considered within its goal?
  • Which DNS record is used to publish a policy that combines SPF and DKIM results to handle unauthenticated emails?
  • Which command is used to display the IP routing table on Windows hosts?
  • Which online sandbox is described as offering interactive reporting and the ability to upload multiple malware samples?
  • Which of the following is primarily a database of phishing-related indicators?
  • Which policy change would prevent unsecured remote access?
  • Which layer focuses on securing data as it moves across networks?
  • What does ping -6 do?
  • Which artifact is used to revoke certificates and inform entities of invalid certificates?
  • Which debugging security tool can be used by black hats to reverse engineer binary files when writing exploits?
  • Why does IoT technology pose a greater risk on a network?
  • Which concept allows using the same credentials to access multiple networks or websites across different organizations, often via a single sign-on?
  • What is the most common goal of SEO poisoning?
  • Which aspect includes network infrastructure, endpoints, servers, identity management, vulnerability management, monitoring and logging?
  • What is the role of DNS?
  • What is used by PKI entities to verify the validity of a digital certificate?
  • In exploitability metrics, which criterion expresses whether the attack requires the involvement of multiple authorities?
  • Which type of firewall works at all layers of the OSI model?
  • Which protocol is used by the Cisco Cyber Threat Defense Solution to collect information about the traffic that traverses the network?
  • OpenVPN is used to provide encrypted tunneling for VPNs. Which of the following options reflects this role?
  • Which statement best describes netstat?
  • NetBIOS is associated with which port range?
  • What best describes a botnet?
  • What is the National Vulnerability Database (NVD)?
  • What is Nslookup commonly used for?
  • Which option names a firewall component associated with OpenBSD Packet Filter?
  • Which criterion in Exploitability reflects the level of access required for a successful exploit?
  • Which DNS record is commonly used to publish DKIM public keys?
  • Defense-in-Depth/Layered Security is best described as?
  • In the OSI model, which layer is responsible for end-to-end communication control?
  • Which statement best describes Snort?
  • Which type of message is sent to all hosts on a remote network?
  • What is Nessus?
  • What does ipconfig /release do?
  • What is Cuckoo Sandbox?
  • Which DNS record type is commonly used to publish security-related information such as DKIM keys and DMARC policies?
  • Which is a capability area in the National Cybersecurity Workforce Framework?
  • Which job would require verification that an alert represents a true security incident or a false positive?
  • TCP port 80 is assigned to which protocol?
  • Which of the following is a packet sniffing tool?
  • What information is typically required to manually connect a mobile device to a secured wireless network?
  • What does the MIME standard define?
  • TCP port 443 is assigned to which protocol?
  • MS-SQL uses which port(s)?
  • TCP port 23 is used by:
  • Which command can display the NetBIOS over TCP/IP connection data?
  • In the Security Onion architecture, which tool is known as a network traffic analysis tool?
  • Which components are typically included in Internet of Things deployments?
  • A host is transmitting a broadcast, which hosts will receive it?
  • What does PCI DSS stand for and what is its focus?
  • What is the best approach to prevent a compromised IoT device from maliciously accessing data and devices on a local network?
  • What does MTBF measure?
  • A loopback address is an IP address that indicates your own computer and is used to test TCP/IP configuration on the computer.
  • Which DNS record is used to specify the mail server for a domain?
  • What is Tripwire in IT security?
  • In the TCP/IP conceptual model, which layer is the lowest (closest to the physical medium)?
  • Which of the following is a recognized threat source type?
  • In which document would a statement like 'Windows workstations must have the current security configuration template applied before deployment' most likely belong?
  • TheHarvester is listed as which category of security tools?
  • Which Cisco product is described as an all-in-one web gateway and can block hidden malware from suspicious and legitimate websites?
  • What is the default number of lines displayed by the head command?
  • Which tool can perform real-time traffic and port analysis, and can also detect port scans, fingerprinting and buffer overflow attacks?
  • UDP port 67 is used by?
  • Which statement about ping options -6 and -4 is true?
  • TCP port 143 is used by which protocol?
  • Which tool is used to probe and test a firewall's robustness using specially crafted forged packets?
  • How many layers are in the OSI Reference Model?
  • Which of the following is a type of cyber threat?
  • The chmod command is used to
  • In the SOC's three-tier model, who is Tier 3?
  • Which logs are most likely to reveal the IP address and MAC address of devices on the local network?
  • Which TCP/IP layer is responsible for routing packets between networks?
  • What parameter identifies the application when a client requests a service from a remote server?
  • What is hardening in cybersecurity?
  • What is the Nmap utility used for?
  • What does an A record map?
  • What should be checked first when a laptop connects to a public Wi‑Fi network?
  • Which tool provides a console to view alerts generated by network security monitoring tools?
  • Which security policy would address the process of updating AP configurations?
  • Which statement best describes a Context Aware Application Firewall?
  • Which of the following is a packet sniffing tool listed among the material's examples?
  • Which item is a type of cyber threat involving errors in software causing vulnerabilities?
  • Which term is a defense in depth strategy?
  • Which Act focuses on protecting consumer financial information and requires financial institutions to explain their privacy practices?
  • What does MTTD stand for and measure?
  • What does a TXT DNS record typically store?
  • Which protocols operate on the Application layer of the TCP/IP model?
  • Why should an organization conform to a standard data governance framework?
  • Which protocol is commonly used to monitor and manage network devices and can reset passwords or change device baselines?
  • Which tool is commonly used to discover hosts and services on a network as part of a pentest?
  • TCP port 20 is used by:
  • A synchronized surge of traffic from multiple sources intended to overwhelm a target is best described as what?
  • Hashing is used to generate a fixed-size digest that can be used to verify data integrity.
  • What does ping -4 do?
  • In a penetration test, which phase focuses on gathering information about the target network or device?
  • What does SPF primarily verify?
  • Which of the following is a network scanning tool?
  • In the SOC three-tier model, which role is assigned to Tier 1?
  • Which stage of the kill chain used by attackers focuses on the identification and selection of targets?
  • What does the onion analogy in cybersecurity primarily illustrate?
  • Which technology creates a security token that allows a user to log into a web application using credentials from a social media website?
  • What is the primary use of a loopback address in testing network software?
  • Which Cisco service provides information about security incident detection rule sets for tools such as Snort, ClamAV, and SpamCop?
  • Under CFAA, which access is criminal?
  • NetFlow data is commonly used to collect and analyze traffic flow data. Which option describes this use?
  • Which category includes policies, procedures, standards, user education, incident response, disaster recovery, compliance and physical security?
  • What does ping -t do?
  • What policy change would ensure servers are updated with the latest patches at regular intervals?
  • Which threat category involves events like floods, earthquakes that disrupt operations?
  • The ping utility is commonly used to test what aspects of a network connection?
  • UDP ports 161/162 are used by which protocol?
  • What does ipconfig /renew do?
  • In exploitability metrics, which criterion describes whether multiple authorities must be involved in an exploit?
  • Which set of fields constitutes the five-tuple used in network monitoring?
  • Which Cisco solution provides protection before, during, and after an attack?
  • What is the purpose of output encoding in security coding techniques?
  • UDP port 68 is used by which protocol's client service?
  • Which of the following is a threat source type?
  • In base metrics for exploitability, which description matches attack complexity?
  • What does the -a option of ping do?
  • The route command can
  • Email privacy risk: Including which type of information would most likely compromise patient privacy?
  • Which Exploitability criterion expresses the presence or absence of a user interaction requirement?
  • Which method of wireless authentication can take advantage of identity verification using a Radius server?
  • Which protocol is used to access email on servers and keep content on the server, enabling access from multiple devices?
  • Which threat type arises from the actions of people, not machines?
  • Which statement best describes defense in depth?
  • What is the IPv4 multicast address range?
  • Which of the following is an encryption tool?
  • What are Yara Rules used for?
  • Which type of evidence is traditionally considered the strongest in investigations?
  • Which of the following is NOT one of the three detection tools mentioned for collecting alert data in Security Onion architecture?
  • Which protocol operates at the Transport layer of the TCP/IP model?
  • Which phase involves documenting the incident, assessing impact, and identifying improvements to prevent recurrence?
  • Which tool is a password auditing and recovery application?
  • Which term describes segments of unused network space that are monitored to detect unauthorized traffic?
  • Which is an on-path attack example?
  • What names are given to a database where all cryptocurrency transactions are recorded?
  • In incident response, Reporting is defined as
  • Which command pair obtains a new IP address from a DHCP server?
  • Which security coding technique ensures that data displayed to users will not execute unintended code in the browser?
  • Which of the following is NOT a password cracking tool?
  • The default DHCP configuration on a home wireless router assigns which type of addresses to devices?
  • Which term describes any device that controls or filters traffic going in or out of the network?
  • In incident response, Acquisition is best described as
  • NMAP is an example of which category of security tools?
  • Which item can be managed through Group Policy (GPO) in Windows environments?
  • Which of the following is NOT a private IPv4 address range?
  • What is L0phtcrack?
  • Microsoft SQL Server typically listens on which port range for database connections?
  • What type of system is designed to mislead attackers and collect information about attack methods?
  • What is the Sarbanes-Oxley Act primarily concerned with?
  • Which tool detects vulnerabilities on networks?
  • What is an advantage for small organizations of adopting IMAP instead of POP?
  • Describe HIPAA.
  • Which firewall filters web content requests such as URLs and domain names?
  • Remote Desktop Protocol uses which port for typical connections?
  • What is the main function of the Cisco Security Incident Response Team?
  • Which is the highest layer of the OSI model?
  • Which of the following is NOT a standard Windows event severity level?
  • What type of system is used to contain an attacker to allow them to be monitored?
  • Which protocol uses UDP port 69 for simple file transfer without authentication?
  • What is GFI LANguard?
  • Who typically uses Registered Ports?
  • Which agency administers COPPA?
  • What is obfuscation in security coding?
  • Which sequence correctly lists the OSI layers from the lowest to the highest?
  • COPPA protects privacy of children under what age?
  • Which practice is essential for preventing common web application attacks like SQL Injection and XSS by validating input and using whitelists?
  • In network security, Sniffing refers to what activity?
  • For what purpose would a network administrator use the Nmap tool?
  • Which of the following is an example of a wireless cracking tool?
  • FTK Imager is a forensic tool that can
  • Which device is primarily used to enforce access control by filtering traffic at a network boundary?
  • Which statement best describes the security onion analogy for defense in depth?
  • Standards provide mandatory requirements for how policies are carried out. Which option best describes this concept?
  • In the cybersecurity onion model, which is the first layer to protect?
  • How often should patches be updated and tested?
  • Which technology protects the integrity of data in transit?
  • TCP ports 137-139 are used by which service?
  • Which security mitigation technique involves rotating personnel roles every few months?
  • Which is an example of an on-path attack that can affect mobile devices?
  • Which statement best describes tracert/traceroute?
  • The three open ports 22, 443, and 1521 are commonly associated with which combination of services?
  • Which protocol maps IP addresses to MAC addresses on a local network?
  • Which description best matches the grep command?
  • Which IR phase involves extracting digital contents from a seized device so they may be analyzed?
  • Which option does NOT align with the defense-in-depth approach?
  • What does DMARC rely on to verify emails?
  • Which three protocols are commonly used for email retrieval and sending?
  • Which command is commonly used to troubleshoot domain name servers and retrieve DNS resource records?
  • A sandbox in cybersecurity is best described as...
  • What is a difference between symmetric and asymmetric encryption algorithms?
  • Rootkit detectors are best described as what?
  • What class of IP addresses is used for multicast addressing?
  • Which term describes a more complex decoy system used mainly by research, military, and government organizations?
  • Which option correctly names the ARP command?
  • Which of the following protocols use the Advanced Encryption Standard (AES)?
  • Which statement best describes a DNS attack?
  • Which policy change best prevents unauthorized escalation of privileges?
  • What is DHCP's role in a network?
  • Which activity is associated with monitoring and investigation in security operations?
  • What does input validation involve in security coding techniques?
  • Which statement about port 53 is true?
  • When was COPPA passed by Congress?
  • Which protocol uses TCP port 3389 and UDP port 3389 for remote desktop connections?
  • Which secure media disposition method renders data unrecoverable to permit reuse within the organization?
  • The Electronic Communications Privacy Act (ECPA) aims to protect what?
  • NetFlow is best described as what?
  • Which threat category involves interruptions to power, water, or network connectivity?
  • What is another term for the internet-facing port on a wireless router?
  • The logger command is a Linux utility that
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy