Skip to content

100-160 Practice Questions

Prepare for 100-160 with more than an answer.

140 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$125 USD
Level
Entry-Level (CCST)
Valid for
Lifetime (if earned before July 15, 2025); 5 years (if earned on or after July 15, 2025)
Domains covered on the exam 5
  1. Essential Security Principles20%
  2. Basic Network Security Concepts22%
  3. Endpoint Security Concepts26%
  4. Vulnerability Assessment and Risk Management17%
  5. Incident Handling15%
  1. 1

    A network security analyst observes a massive spike in inbound TCP traffic targeting a web server. The packet capture reveals thousands of packets with the SYN flag set, originating from randomized spoofed IP addresses. The server is responding with SYN-ACK packets, but never receives the final ACK to complete the handshake, causing its connection queue to exhaust. Which type of attack is occurring?

    Show answer details

    Correct answer: C

    A SYN flood is a form of Denial-of-Service (DoS) attack where an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic. The attacker deliberately ignores the server's SYN-ACK responses, leaving half-open connections until the server crashes or stops responding.

    sequenceDiagram participant Attacker participant Server Attacker->>Server: SYN (Spoofed IP 1) Server-->>Attacker: SYN-ACK (Waiting...) Attacker->>Server: SYN (Spoofed IP 2) Server-->>Attacker: SYN-ACK (Waiting...) Note over Server: Connection queue fills up Legitimate users denied
  2. 2

    A malicious user on a local area network (LAN) wants to intercept traffic between a victim's workstation and the default gateway. The attacker broadcasts forged messages on the local network that falsely map the attacker's MAC address to the IP address of the default gateway. What specific network attack is the attacker performing?

    Show answer details

    Correct answer: A

    Address Resolution Protocol (ARP) spoofing (or ARP poisoning) involves sending forged ARP messages over a local area network. This links the attacker's MAC address with the IP address of a legitimate computer or server (like the default gateway), allowing the attacker to intercept, modify, or stop data frames in a Man-in-the-Middle (MITM) attack.

  3. 3

    A network architect is designing a new internal corporate network that will not be directly routable on the public Internet. The architect decides to use RFC 1918 private IPv4 address spaces to enhance security and preserve public IPs. Which TWO of the following address ranges are valid RFC 1918 private IP spaces? (Select TWO)

    Show answer details

    Correct answer: D, E

    According to RFC 1918, the three blocks of private IPv4 address space reserved for internal networks are: 10.0.0.0/8 (10.0.0.0 - 10.255.255.255), 172.16.0.0/12 (172.16.0.0 - 172.31.255.255), and 192.168.0.0/16 (192.168.0.0 - 192.168.255.255). These addresses are not routable on the public Internet, adding a layer of isolation.

    According to RFC 1918, the three blocks of private IPv4 address space reserved for internal networks are: 10.0.0.0/8 (10.0.0.0 - 10.255.255.255), 172.16.0.0/12 (172.16.0.0 - 172.31.255.255), and 192.168.0.0/16 (192.168.0.0 - 192.168.255.255). These addresses are not routable on the public Internet, adding a layer of isolation.

  4. 4

    A Tier 1 SOC analyst at a regional financial institution is reviewing a security incident where a distributed denial-of-service (DDoS) attack overwhelmed the customer-facing banking portal, rendering it inaccessible for four hours. No data was stolen or altered during the incident. Which core component of the CIA triad was primarily compromised in this scenario?

    Show answer details

    Correct answer: D

    Availability ensures that authorized users have reliable and timely access to systems, data, and resources when needed. A DDoS attack specifically targets the availability of a service by overwhelming it with traffic, preventing legitimate users from accessing the portal. Because no data was stolen (Confidentiality) or unauthorizedly modified (Integrity), Availability is the only component of the CIA triad compromised here.

  5. 5

    A cybersecurity intelligence report indicates that a highly sophisticated, well-funded group is attempting to steal proprietary aerospace blueprints from a defense contractor. The group uses custom-developed malware and maintains persistent, stealthy access over several months. Based on these characteristics, which type of threat actor is MOST likely responsible?

    Show answer details

    Correct answer: D

    Nation-state actors are typically highly sophisticated, well-funded, and operate with the backing of a government. They often target intellectual property, military secrets, or critical infrastructure, utilizing Advanced Persistent Threats (APTs) to maintain stealthy, long-term access. Hacktivists are driven by ideological motives, script kiddies lack sophistication, and insider threats originate from within the organization.

  6. 6

    During a security briefing, an IT support technician is asked to identify the defining characteristics of a botnet. Which TWO of the following attributes are essential components of a botnet architecture? (Select TWO)

    Show answer details

    Correct answer: B, C

    Botnets rely on a Command and Control (C2) infrastructure to send instructions to infected devices. They also consist of a network of compromised devices (zombies) that execute the attacker's commands, such as launching DDoS attacks or sending spam.

    Botnets rely on a Command and Control (C2) infrastructure to send instructions to infected devices. They also consist of a network of compromised devices (zombies) that execute the attacker's commands, such as launching DDoS attacks or sending spam.

Create an account to continue.