Which wireless security protocol provides the strongest protection for a home or small business network?
The CCST Cybersecurity Study Guide explains that WPA3 is the most current and secure Wi-Fi Protected Access protocol, offering stronger encryption and better protection against brute-force attacks compared to earlier versions.
'WPA3 improves wireless security by using more robust encryption methods and protections against offline password guessing, making it the recommended protocol for securing modern Wi-Fi networks.'
(CCST Cybersecurity, Basic Network Security Concepts, Wireless Security Protocols section, Cisco Networking Academy)
A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?
The CCST Cybersecurity course highlights that signs of brute-force attacks followed by successful access require immediate account security actions and an investigation to determine if other systems were accessed.
'When suspicious login activity is detected, immediate containment steps such as password resets and log analysis are necessary to limit damage and identify the extent of the compromise.'
(CCST Cybersecurity, Incident Handling, Account Compromise Response section, Cisco Networking Academy)
You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run internet searches to uncover domain information. You also use social media to gather details about the company and its employees.
Which type of reconnaissance activities are you performing?
The CCST Cybersecurity Study Guide explains that reconnaissance is the process of collecting information about a target before attempting exploitation.
'Passive reconnaissance is conducted without directly engaging with the target systems. Examples include reviewing public websites, examining HTML source code, querying public DNS records, and using social media to gather information. Since no packets are sent directly to the target system, it reduces the risk of detection.'
(CCST Cybersecurity, Vulnerability Assessment and Risk Management, Reconnaissance Techniques section, Cisco Networking Academy)
Passive (A) is correct because all actions described --- viewing public pages, searching online, and checking social media --- involve no direct interaction that could alert the target.
Active (B) would involve direct probing, like port scans or vulnerability scans.
Offline (C) is not an official reconnaissance classification in this context.
Invasive (D) is a general term and not used as a standard reconnaissance category in CCST material.
You are collecting data after a suspected intrusion on the local LAN.
You need to capture incoming IP packets to a file for an investigator to analyze.
Which two tools should you use? (Choose 2.)
The CCST Cybersecurity Study Guide specifies that both Wireshark and tcpdump are packet capture tools that can record network traffic to a file for later analysis.
'Wireshark provides a graphical interface for packet capture and analysis. Tcpdump is a command-line tool that captures packets for detailed offline review.'
(CCST Cybersecurity, Incident Handling, Network Traffic Analysis section, Cisco Networking Academy)
A is correct: Wireshark is widely used for packet capture and analysis.
B is correct: tcpdump is a CLI-based packet capture tool.
C (Nmap) is for network scanning, not packet capture.
D (netstat) displays network connections and ports but does not capture packets.
You need a software solution that performs the following tasks:
Compiles network data
Logs information from many sources
Provides orchestration in the form of case management
Automates incident response workflows
What product should you use?
The CCST Cybersecurity Study Guide explains that SOAR (Security Orchestration, Automation, and Response) platforms integrate data from multiple tools and sources, support case management, and automate security workflows for faster incident response.
'SOAR solutions provide orchestration, automation, and response capabilities. They collect security data from multiple systems, enable analysts to manage incidents, and automate repetitive tasks in the response process.'
(CCST Cybersecurity, Incident Handling, Security Automation Tools section, Cisco Networking Academy)
A (SIEM) collects and correlates security logs but lacks full orchestration and automated response capabilities.
B is correct: SOAR adds orchestration, case management, and automated incident response.
C (NextGen IPS) focuses on intrusion prevention, not orchestration.
D (Snort) is an open-source intrusion detection/prevention tool, not an orchestration platform.
Kimberly Evans
7 hours agoGeorge Jackson
11 days agoElizabeth Thomas
1 month agoMichael Campbell
1 month agoRichard Thompson
2 months agoTiffany Thomas
2 months agoRyan Rodriguez
3 months agoHeather Hernandez
3 months agoCynthia Morgan
4 months agoElizabeth Johnson
4 months agoEric Evans
4 months agoChristopher Bailey
4 months agoSusan Hernandez
4 months agoBrian King
4 months agoSherill
5 months agoSvetlana
5 months agoFranklyn
5 months agoEvangelina
6 months agoSang
6 months agoRolf
6 months agoFreeman
6 months agoBenton
7 months agoDannie
7 months agoIrma
7 months agoKaitlyn
7 months agoLashawn
8 months agoMelvin
8 months agoArlen
8 months agoDiego
8 months agoColton
9 months agoMing
9 months agoCornell
9 months agoGlenn
9 months agoKristofer
10 months agoLezlie
10 months agoAlpha
10 months agoLeeann
10 months agoDanica
11 months agoLisbeth
11 months agoSamira
11 months agoWendell
11 months agoClorinda
11 months agoVilma
11 months agoKenneth
1 year agoBrittni
1 year agoGlen
1 year ago