Question 1
Which tool is a packet sniffer?
Correct Answer:
Wireshark
Explanation:
Packet sniffing involves capturing live network traffic and inspecting the contents of packets. Wireshark is designed exactly for that: it captures packets from the network, decodes many protocols, and presents them in a searchable, filterable interface for analysis. This makes it the primary tool for sniffing and traffic analysis. The other tools serve different purposes. Nmap focuses on discovering hosts and services on a network. Hping is used to craft and send custom packets to test defenses or measure network responses. Scapy is a flexible packet manipulation toolkit that can sniff as part of its capabilities but is primarily aimed at building and sending packets in Python.
Question 2
Which term describes a more complex decoy system used mainly by research, military, and government organizations?
Correct Answer:
Honeypot
Explanation:
A honeypot is a deliberately vulnerable resource placed inside a network to attract attackers, with the purpose of observing their methods, tools, and behavior. This makes it a more complex decoy system, especially when scaled into a honeynet—multiple interlinked decoys that mimic real systems. Researchers, military, and government organizations use this approach to study threats, gather intelligence on attack techniques, and improve defenses. In contrast, a DNS record is just data within the Domain Name System, a firewall is a protective device that blocks or filters traffic, and a canary trap is a leakage-detection deception tactic aimed at identifying insiders rather than providing a monitored decoy environment for threat actors.
Question 3
Which protocol is used by the Cisco Cyber Threat Defense Solution to collect information about the traffic that traverses the network?
Correct Answer:
NetFlow
Explanation:
NetFlow is the protocol used to export flow-based visibility into traffic traversing the network. A flow is defined by identifiers like source and destination IP addresses and ports, the transport protocol, and other fields; NetFlow records also include statistics such as bytes, packets, and duration. This flow-level data lets Cisco CTD see who is talking to whom, when, and how much, enabling effective threat detection and traffic analysis without capturing full packet contents. SNMP is for device management, not traffic flows; sFlow provides sampled data which can miss many flows; IPFIX is the standard version of flow data, but NetFlow is the protocol most closely associated with Cisco CTD in this context.
Question 4
Which command is commonly used to troubleshoot domain name servers and retrieve DNS resource records?
Correct Answer:
Nslookup
Explanation:
When diagnosing name resolution problems, you want a tool that talks directly to DNS servers to ask for specific records. That’s what nslookup does. It’s a command-line utility built to query DNS servers and retrieve resource records, such as A records (mapping a domain to an IP), MX records (mail servers), NS records (name servers), CNAMEs, and more. You can run it simply to see what IP address a domain resolves to, or specify the record type to verify particular DNS data, for example asking for MX records for a domain or pointing nslookup at a specific DNS server to compare results. This targeted capability makes it the go-to tool for DNS troubleshooting and validation. Tools like netstat focus on current network connections, not DNS data; grep is a text-search utility; and route deals with routing tables. None of those directly retrieve DNS resource records to diagnose name resolution.
Question 5
FTK Imager is a forensic tool that can
Correct Answer:
FTK Imager is a forensic tool that can perform a forensically sound acquisition, verify it with an MD5 hash, and preview files in read-only mode
Explanation:
Preserving evidence integrity during acquisition is essential in digital forensics. FTK Imager is a forensic tool that can create a forensically sound image of storage media, verify the copy using an MD5 hash, and allow you to preview files in read-only mode. This combination ensures the collected data is an exact, unaltered replica and lets investigators inspect contents without risking modification to the source. It does not monitor live network traffic, it does not recover deleted files without proper authorization, and it does not automatically patch operating system vulnerabilities.
Question 1
Exam overview

About this Exam

Prepare with the CCST Cybersecurity Practice Test practice quiz. This question bank includes 10 questions covering tool, protocol, domain, port, and server. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

CCST Cybersecurity Practice Test

This practice set contains 10 questions from the matching question bank and focuses on tool, protocol, domain, port, and server. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions