WorksheetsCisco CCST Objective 1
Total questions: 10
Worksheet time: 5mins
Which of the following best defines a vulnerability in cybersecurity?
A. An action that causes damage to a system.
B. A weakness that can be exploited by threats.
C. A protective measure against cyberattacks.
D. A process for encrypting sensitive data.
What are the three components of the CIA Triad?
Confidentiality, Integrity, and Availability.
Control, Identification, and Authorization.
Cryptography, Intrusion Detection, and Access Control.
Compliance, Inspection, and Authentication.
Which type of attack involves sending deceptive emails to trick users into revealing sensitive information?
Phishing
Denial of Service (DoS)
Brute Force Attack
Man-in-the-Middle Attack
Which security principle refers to applying multiple layers of security controls to protect systems?
A. Principle of Least Privilege
B. Zero Trust Security
C. Defense-in-Depth
D. Single Sign-On
What is the primary purpose of hardening a system?
To remove outdated hardware components
To make a system more resilient against attacks
To allow external users easier access
To decrease the complexity of security controls
Which of the following is an example of an insider threat?
A. A hacker using brute force to guess passwords.
B. An employee leaking confidential data to competitors.
C. A botnet performing a denial-of-service attack.
D. A phishing attack targeting an organization's employees.
Which of the following best describes an Advanced Persistent Threat (APT)?
A. A short-lived attack that exploits system misconfigurations.
B. A low-level threat that affects individual devices.
C. A continuous, stealthy attack by a skilled adversary.
D. A ransomware attack that encrypts data and demands payment.
Which of the following is NOT an example of a social engineering attack?
Tailgating
Phishing
Smishing
SQL Injection
Which security principle ensures that data is accessible to authorized users when needed?
Integrity
Confidentiality
Availability
Encryption
What is the primary goal of an attacker using a botnet?
To execute a coordinated attack using multiple compromised devices.
To socially engineer employees into giving out passwords.
To infect a single system with malware.
To encrypt data and demand a ransom.
