Browse all practice questions for the CCST Cybersecurity Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CCST Cybersecurity Practice Test 2026 – Comprehensive Exam Prep course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which TCP/IP application layer protocol is commonly used to transfer files between a client and a server?
  • Which policy change would prevent the continued use of weak wireless encryption such as WEP?
  • Which technology enables accurate timestamping of network events by synchronizing time across devices?
  • Which of the following is the OpenBSD Packet Filter?
  • The default DHCP configuration on a home wireless router assigns which type of addresses to devices?
  • Which Cisco service provides information about security incident detection rule sets for tools such as Snort, ClamAV, and SpamCop?
  • During the deployment phase of an asset's lifecycle, what happens to the asset?
  • What is the role of DNS?
  • In the TCP/IP conceptual model, which layer is the lowest (closest to the physical medium)?
  • In incident response, what is the primary goal of the Recovery phase?
  • The HTTP status code 200 indicates what about the client request?
  • Which activity is associated with monitoring and investigation in security operations?
  • Which item is NOT a listed type of cyber threat?
  • What term is used to record the order of evidence handling, by whom, and the nature of the handling?
  • Which is an on-path attack example?
  • Which statement about port 53 is true?
  • Which firewall filters traffic based on the user, device, role, application, and threat profile?
  • Which term describes segments of unused network space that are monitored to detect unauthorized traffic?
  • Which option does NOT align with the defense-in-depth approach?
  • Which job would require verification that an alert represents a true security incident or a false positive?
  • Using the Common Vulnerability Scoring System, which score indicates the most critical vulnerability?
  • TCP port 110 is used by which protocol?
  • What is DHCP's role in a network?
  • Which is a capability area in the National Cybersecurity Workforce Framework?
  • In exploitability metrics, which criterion describes whether multiple authorities must be involved in an exploit?
  • What is another term for the internet-facing port on a wireless router?
  • Which command is used to display the IP routing table on Windows hosts?
  • Which item is a type of cyber threat involving errors in software causing vulnerabilities?
  • CNAME records are primarily used to?
  • Which online sandbox is described as offering interactive reporting and the ability to upload multiple malware samples?
  • Which tool is described as an open source malware analysis tool that can run locally on the network?
  • Who typically uses Registered Ports?
  • What is the purpose of a DNS sinkhole in security?
  • Which IR phase results in the formal written documentation?
  • What does ipconfig /release do?
  • Which secure media disposition method renders data unrecoverable to permit reuse within the organization?
  • Which DNS record is commonly used to publish DKIM public keys?
  • TCP ports 137-139 are used by which service?
  • Which DNS record would an email server query to locate the destination mail server for a domain?
  • Which type of firewall works at all layers of the OSI model?
  • What is Cuckoo Sandbox?
  • What policy change would ensure servers are updated with the latest patches at regular intervals?
  • The Electronic Communications Privacy Act (ECPA) aims to protect what?
  • What best defines the Internet of Things (IoT)?
  • What is a Denial-of-Service (DoS) attack?
  • TCP port 143 is used by which protocol?
  • What is the best approach to prevent a compromised IoT device from maliciously accessing data and devices on a local network?
  • The procedure of developing controls as vulnerabilities are discovered to prevent exploitation is known as
  • Which command is used to view the NetBIOS name cache?
  • In FTK Imager, which mechanism is used to verify the integrity of the acquired data?
  • What does MTBF measure?
  • Which practice is essential for preventing common web application attacks like SQL Injection and XSS by validating input and using whitelists?
  • Which DNS record indicates the DNS servers assigned to a zone?
  • Microsoft SQL Server typically listens on which port range for database connections?
  • What does CIPA require for federal funding?
  • Nessus is listed as which type of tool?
  • What parameter identifies the application when a client requests a service from a remote server?
  • Which statement best describes a Context Aware Application Firewall?
  • Cisco Advanced Malware Protection (AMP) provides which of the following?
  • TCP port 1701 is used by which VPN protocol?
  • Cisco Web Security Appliance (WSA) is best described as?
  • Which type of cipher encrypts plaintext one byte or one bit at a time?
  • Which statement best describes tracert/traceroute?
  • Which protocol is used to access email on servers and keep content on the server, enabling access from multiple devices?
  • Which tool provides a list of open ports on network devices?
  • Which of the following is the IPv4 link-local address range?
  • What best describes a Man-in-the-Middle (MitM) attack?
  • What is obfuscation in security coding?
  • What is the purpose of output encoding in security coding techniques?
  • The chmod command is used to
  • What does ping -6 do?
  • What are the two important components of a PKI used in network security?
  • Which agency administers COPPA?
  • What is the general purpose of encryption tools as described?
  • For what purpose would a network administrator use the Nmap tool?
  • Which action would violate the CFAA?
  • In incident response, Reporting is defined as
  • A password cracker is software that repeatedly makes guesses in order to crack the password.
  • Which protocols operate at the Network Access layer of the TCP/IP model?
  • NetBIOS is associated with which port range?
  • What type of system is used to contain an attacker to allow them to be monitored?
  • Which term is a defense in depth strategy?
  • Email privacy risk: Including which type of information would most likely compromise patient privacy?
  • What is a feature of the ANY.RUN malware sandbox?
  • Which criterion in Exploitability reflects the level of access required for a successful exploit?
  • Which tool is used to probe and test a firewall's robustness using specially crafted forged packets?
  • In the cybersecurity onion model, which is the first layer to protect?
  • Which tool is commonly used to discover hosts and services on a network as part of a pentest?
  • DNS uses which port and transport protocols?
  • Which type of evidence is traditionally considered the strongest in investigations?
  • FERPA was enacted in which year?
  • Which set of fields constitutes the five-tuple used in network monitoring?
  • Which DNS record is used to publish a policy that combines SPF and DKIM results to handle unauthenticated emails?
  • Which of the following best describes an Endpoint Security Suite?
  • OpenVPN is used to provide encrypted tunneling for VPNs. Which of the following options reflects this role?
  • What is a difference between symmetric and asymmetric encryption algorithms?
  • Which is an example of an on-path attack that can affect mobile devices?
  • What is a production honeypot primarily used for?
  • In the SOC's three-tier model, who is Tier 3?
  • Which sequence correctly lists the OSI layers from the lowest to the highest?
  • Which KPI metric does SOAR use to measure the time required to stop the spread of malware in the network?
  • Which service commonly runs on port 22?
  • Which policy ensures that passwords are not reused across different applications?
  • What is DKIM used for?
  • Which option correctly describes the arp command's purpose?
  • A synchronized surge of traffic from multiple sources intended to overwhelm a target is best described as what?
  • Which tool would you use to visualize the path taken by packets to a destination, showing each intermediate router (hop)?
  • Which debugging security tool can be used by black hats to reverse engineer binary files when writing exploits?
  • Which device is primarily used to enforce access control by filtering traffic at a network boundary?
  • Which command is commonly used to troubleshoot domain name servers and retrieve DNS resource records?
  • How many layers are in the OSI Reference Model?
  • TCP port 443 is assigned to which protocol?
  • Which Cisco product is described as an all-in-one web gateway and can block hidden malware from suspicious and legitimate websites?
  • Which tool is used for real-time traffic analysis and can detect port scans, fingerprinting and buffer overflow attacks?
  • A cyberanalyst is looking for an open source malware analysis tool that can run locally on the network. Which tool would meet the needs of the cyberanalyst?
  • Which IR phase involves extracting digital contents from a seized device so they may be analyzed?
  • What does ping -t do?
  • Which threat category involves events like floods, earthquakes that disrupt operations?
  • Which item can be managed through Group Policy (GPO) in Windows environments?
  • What names are given to a database where all cryptocurrency transactions are recorded?
  • Which layer focuses on securing data as it moves across networks?
  • Knowingly accessing any computer used in or affecting interstate or foreign commerce without permission is a CFAA violation.
  • Which techniques can be used to enhance database security?
  • NetFlow data is commonly used to collect and analyze traffic flow data. Which option describes this use?
  • Which of the following is a technical control to support secure teleworker access to the corporate network?
  • Which of the following is an encryption tool?
  • Which PKI component is responsible for issuing and managing digital certificates?
  • UDP ports 161/162 are used by which protocol?
  • Which statement best describes a DDoS attack?
  • Which protocol uses TCP port 3389 and UDP port 3389 for remote desktop connections?
  • Which option correctly names the ARP command?
  • What does the -a option of ping do?
  • What type of system is designed to mislead attackers and collect information about attack methods?
  • Which tool is a password auditing and recovery application?
  • Which components are typically included in Internet of Things deployments?
  • In a penetration test, the initial phase focuses on documenting the target's current state to learn as much as possible.
  • Which statement best describes a DNS attack?
  • Which description best matches the grep command?
  • MTTC refers to the average time between the start and resolution of an incident (sometimes called MTTR for mean-time-to-resolve).
  • What is the primary purpose of a packet analyzer?
  • Which term describes deliberate actions to damage an organization's operations?
  • The logger command is a Linux utility that
  • The cat command is used to
  • Which technology protects the integrity of data in transit?
  • Describe HIPAA.
  • Which authentication protocol is well suited to untrusted networks and encrypts authentication traffic by default?
  • Which range is the loopback address range for IPv4?
  • Which of the following is a packet sniffing tool?
  • The Gramm-Leach-Bliley Act (GLBA) primarily governs privacy and protection of what type of information?
  • What is hardening in cybersecurity?
  • Which logs are most likely to reveal the IP address and MAC address of devices on the local network?
  • TCP port 25 is used by?
  • In the SOC three-tier model, which role is assigned to Tier 1?
  • Which protocol is used to send error messages and is commonly used with ping to test connectivity?
  • In the Security Onion architecture, which tool is known as a network traffic analysis tool?
  • Which of the following is a private IPv4 address block within the 172 range?
  • Which of the following is NOT a private IPv4 address range?
  • Which statement best describes the function of a protocol analyzer?
  • Which is the highest layer of the OSI model?
  • What should be checked first when a laptop connects to a public Wi‑Fi network?
  • Which term describes an attack that uses a network of compromised devices to flood a target's resources?
  • IPv6 link-local addresses begin with which prefix?
  • Which range defines Well Known Ports?
  • What is the main function of the Cisco Security Incident Response Team?
  • Which technology creates a security token that allows a user to log in to a desired web application using credentials from a social media website?
  • COPPA took effect in April 2000.
  • A loopback address is an IP address that indicates your own computer and is used to test TCP/IP configuration on the computer.
  • Which protocol operates at the Transport layer of the TCP/IP model?
  • Which KPI metric does SOAR use to measure the average time that it takes to stop and remediate a security incident?
  • TheHarvester is listed as which category of security tools?
  • Which category includes policies, procedures, standards, user education, incident response, disaster recovery, compliance and physical security?
  • What is GFI LANguard?
  • What is IMPACT in cybersecurity?
  • What does ipconfig /renew do?
  • Which security coding technique is described as replacing sensitive data with realistic fictional data?
  • What is used by PKI entities to verify the validity of a digital certificate?
  • Which of the following protocols use the Advanced Encryption Standard (AES)?
  • UDP port 69 is used by which protocol?
  • Which option names a firewall component associated with OpenBSD Packet Filter?
  • Which of the following is an example of a password cracking tool?
  • Which tool is commonly used to scan systems for software vulnerabilities?
  • Which protocols operate on the Application layer of the TCP/IP model?
  • Which protocol maps IP addresses to MAC addresses on a local network?
  • What is the Cisco Email Security Appliance (ESA) designed to do?
  • What is the most common goal of SEO poisoning?
  • Which threat category involves stealing physical or data assets?
  • What is the default number of lines displayed by the tail command?
  • In exploitability metrics, which criterion expresses whether the attack requires the involvement of multiple authorities?
  • In the OSI model, which layer is responsible for end-to-end communication control?
  • Which statement best describes defense in depth?
  • OpenVPN is listed as an encryption tool used for what purpose?
  • What is Nessus?
  • Which statement best describes netstat?
  • In incident response, what is the primary goal of Seizure?
  • Which range is used for dynamic/private (ephemeral) ports?
  • In which document would a statement like 'Windows workstations must have the current security configuration template applied before deployment' most likely belong?
  • Which option correctly identifies the two tools that can detect anomalous behavior, command and control traffic, and infected hosts when used together?
  • The three open ports 22, 443, and 1521 are commonly associated with which combination of services?
  • Which DNS record is used to specify the mail server for a domain?
  • Which statement best describes the function of a protocol analyzer?
  • Which tool provides a console to view alerts generated by network security monitoring tools?
  • Which protocol is commonly used to monitor and manage network devices and can reset passwords or change device baselines?
  • FTK Imager is a forensic tool that can
  • Which tool can perform real-time traffic and port analysis, and can also detect port scans, fingerprinting and buffer overflow attacks?
  • The route command can
  • What does a TXT DNS record typically store?
  • Which term describes a more complex decoy system used mainly by research, military, and government organizations?
  • What is Sguil used for?
  • Which policy changes would help prevent passwords from being cracked within six hours?
  • Rootkit detectors are best described as what?
  • Standards provide mandatory requirements for how policies are carried out. Which option best describes this concept?
  • In the Diamond Model, which four elements constitute its framework?
  • Which security policy would address the process of updating AP configurations?
  • What does an A record map?
  • MS-SQL uses which port(s)?
  • Hashing is used to generate a fixed-size digest that can be used to verify data integrity.
  • TCP port 20 is used by:
  • Which item is NOT typically included in an Endpoint Security Suite?
  • Which of the following is a recognized threat source type?
  • Mean Time to Repair (MTTR) measures?
  • Which statement best describes PhishSigs as a resource?
  • A software company uses a public cloud service for hosting software development and deployment services. The company is concerned that software code in development might leak to competitors and result in the loss of intellectual property. Which security coding techniques can the company implement to address the concern?
  • What does SPF primarily verify?
  • What is the National Vulnerability Database (NVD)?
  • Which TCP/IP layer is responsible for routing packets between networks?
  • Which phase of incident response involves containment, eradication, and recovery?
  • Which of the following is NOT a standard Windows event severity level?
  • What is the correct order of the four steps of Incident Response?
  • What is L0phtcrack?
  • NMAP is an example of which category of security tools?
  • Which statement best describes Snort?
  • Which three protocols are commonly used for email retrieval and sending?
  • What does PCI DSS stand for and what is its focus?
  • Which act provides public access to federal agency records, subject to exemptions?
  • A host is transmitting a broadcast, which hosts will receive it?
  • UDP port 68 is used by which protocol's client service?
  • Which of the following is an encryption tool?
  • What is the recommended network design to minimize risk from IoT devices with internet access?
  • Which concept allows using the same credentials to access multiple networks or websites across different organizations, often via a single sign-on?
  • Which policy change best prevents unauthorized escalation of privileges?
  • In a penetration test, which phase focuses on gathering information about the target network or device?
  • What is a canary trap used for?
  • Under CFAA, which access is criminal?
  • Which tool detects vulnerabilities on networks?
  • At which layer of the TCP/IP model do devices such as switches operate, along with PPP and ARP?
  • What is Tripwire in IT security?
  • What is ping command used for?
  • What does the onion analogy in cybersecurity primarily illustrate?
  • In the five-tuple description, which elements are included?
  • What is Nslookup commonly used for?
  • What is the Nmap utility used for?
  • Which address class corresponds to experimental addresses?
  • Which of the following is an example of a wireless cracking tool?
  • Why does IoT technology pose a greater risk on a network?
  • Which DNS record type is commonly used to publish security-related information such as DKIM keys and DMARC policies?
  • What are Yara Rules used for?
  • Which destination IPv4 address does a DHCPv4 client use to send the initial DHCP Discover packet when searching for a server?
  • COPPA protects privacy of children under what age?
  • Which artifact is used to revoke certificates and inform entities of invalid certificates?
  • What does MTTD stand for and measure?
  • In incident response, Acquisition is best described as
  • Which statement best defines an IP address spoofing attack?
  • Which statement best describes camouflage in security coding techniques?
  • Which DNS record maps one domain to another as an alias?
  • Which protocol is used by the Cisco Cyber Threat Defense Solution to collect information about the traffic that traverses the network?
  • Which threat type arises from the actions of people, not machines?
  • Which phase involves documenting the incident, assessing impact, and identifying improvements to prevent recurrence?
  • Which of the following statements correctly describes ipconfig on Windows?
  • What is the effect of ipconfig /renew?
  • Which statement best describes the Computer Fraud and Abuse Act (CFAA) of 1986?
  • Which tool is commonly used to crack wireless networks?
  • NetFlow provides information that helps security teams analyze traffic patterns. Which description best captures NetFlow's purpose?
  • What is the IPv4 address 127.0.0.1 commonly known as?
  • Remote Desktop Protocol uses which port for typical connections?
  • In base metrics for exploitability, which description matches attack complexity?
  • TCP port 80 is assigned to which protocol?
  • Which statement best describes the security onion analogy for defense in depth?
  • Which policy change would prevent unsecured remote access?
  • Which threat category involves interruptions to power, water, or network connectivity?
  • Which command can display the NetBIOS over TCP/IP connection data?
  • In the Diamond Model, which element represents the means by which the attacker can inflict harm (tools, techniques, and capabilities)?
  • What is the default number of lines displayed by the head command?
  • Which criterion expresses whether multiple authorities must be involved in an exploit?
  • Why should an organization conform to a standard data governance framework?
  • In incident response, Analysis is defined as
  • What does the MIME standard define?
  • What is the primary use of a loopback address in testing network software?
  • Which organization ensures PCI DSS requirements are enforced for merchants and service providers?
  • Which range defines Registered Ports?
  • Which Act focuses on protecting consumer financial information and requires financial institutions to explain their privacy practices?
  • Which tool is a packet sniffer?
  • If a SOC has a goal of 99.999% uptime, approximately how many minutes of downtime per year is considered within its goal?
  • Which SDLC model is described as repeating four phases (requirements gathering, design, build, evaluation)?
  • Which type of security control focuses on people and processes rather than technology?
  • To protect intellectual property in development hosted on a public cloud, which practice is recommended?
  • Which of the following is a type of cyber threat?
  • What is an advantage for small organizations of adopting IMAP instead of POP?
  • Which term describes networks of compromised computers controlled by an attacker?
  • Which of the following is a packet crafting tool?
  • During which phase of the incident response process is evidence most likely gathered to support legal action?
  • When was COPPA passed by Congress?
  • Which phase focuses on preparation and prevention to minimize security incidents?
  • Which SDLC model uses linear development concepts in an iterative, four-phase process?
  • Which threat category involves issues with physical components or devices?
  • What does ping -4 do?
  • Which type of security system provides real-time reporting and long-term analysis of security events in an enterprise?
  • Which aspect includes network infrastructure, endpoints, servers, identity management, vulnerability management, monitoring and logging?
  • Which statement best describes End Point Detection and Response (EDR)?
  • Which policy action is appropriate when an employee leaves the company?
  • What is the purpose of vulnerability scanners?
  • Which protocol uses UDP port 69 for simple file transfer without authentication?
  • What information is typically required to manually connect a mobile device to a secured wireless network?
  • Which statement correctly describes the difference between ping and traceroute?
  • Nbstat is a utility that
  • Which of the following is a network scanning tool?
  • Which method of wireless authentication can take advantage of identity verification using a Radius server?
  • Which Exploitability criterion expresses the presence or absence of a user interaction requirement?
  • Which of the following is an example of a network scanning tool?
  • The ping utility is commonly used to test what aspects of a network connection?
  • In network security, Sniffing refers to what activity?
  • What does input validation involve in security coding techniques?
  • Which of the following is a packet sniffing tool listed among the material's examples?
  • Which of the following is NOT listed as a recovery-control example?
  • Which of the following is primarily a database of phishing-related indicators?
  • What best describes a botnet?
  • UDP port 67 is used by?
  • Which protocol runs over port 22 as a subsystem?
  • Which command pair obtains a new IP address from a DHCP server?
  • What class of IP addresses is used for multicast addressing?
  • Which term describes any device that controls or filters traffic going in or out of the network?
  • What is the Sarbanes-Oxley Act primarily concerned with?
  • Which action should an organization take to improve wireless security?
  • What are the four steps of Incident Response?
  • Which of the following is NOT one of the three detection tools mentioned for collecting alert data in Security Onion architecture?
  • In defense in depth, which term represents the idea of providing multiple overlapping protections?
  • Which security mitigation technique involves rotating personnel roles every few months?
  • Which of the following is a threat source type?
  • Which technology creates a security token that allows a user to log into a web application using credentials from a social media website?
  • Defense-in-Depth/Layered Security is best described as?
  • Which stage of the kill chain used by attackers focuses on the identification and selection of targets?
  • Which log type is described as a comma-delimited text file containing entries with fields such as ID, Date, Time, Description, IP Address, Host Name, and MAC Address?
  • What is a SIEM system used for?
  • TCP port 23 is used by:
  • TCP port 21 is used by:
  • What does DMARC rely on to verify emails?
  • Which security coding technique ensures that data displayed to users will not execute unintended code in the browser?
  • In the SOC's three-tier model, who is Tier 2?
  • Which firewall filters web content requests such as URLs and domain names?
  • What does ARP stand for?
  • Which statement about ping options -6 and -4 is true?
  • Which remote access method is considered secure according to policy?
  • How often should patches be updated and tested?
  • NetFlow is best described as what?
  • What is the IPv4 multicast address range?
  • A sandbox in cybersecurity is best described as...
  • Which of the following is NOT a password cracking tool?
  • Which Cisco solution provides protection before, during, and after an attack?
  • Which type of message is sent to all hosts on a remote network?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy