Certified Cybersecurity Technician (CCT) Free Sample Questions

20 free sample questions248 in the full practice test

Try simulator

212-82 Sample Questions

  1. Question 1

    A cybersecurity technician at a financial services firm is tasked with implementing a technical control to prevent unauthorized devices from connecting to the corporate wired network. The solution must automatically assess the security posture of any device attempting to connect and place non-compliant devices into a quarantined VLAN for remediation. Which of the following technologies is best suited to meet these requirements?

    Answer and explanation

    Correct answer: B

    Network Access Control (NAC) is the correct solution. NAC systems are designed to enforce security policies on devices seeking to access network resources. They can check for compliance (e.g., updated antivirus, OS patches) and use 802.1X for port-based authentication, automatically quarantining non-compliant devices. An IPS inspects traffic for malicious activity, a proxy server mediates client requests to the internet, and a VPN provides secure remote access.

  2. Question 2

    A technician is analyzing a packet capture from a host experiencing slow network performance. They observe a large number of TCP packets with the SYN flag set being sent to a single server port, but very few corresponding SYN/ACK replies. The source IP addresses of these packets are varied and appear to be spoofed. What type of network event is most likely occurring?

    Answer and explanation

    Correct answer: C

    The scenario describes a classic TCP SYN flood, a type of Denial of Service (DoS) attack. The attacker sends a high volume of SYN packets, often with spoofed source IPs, to overwhelm the server's connection table (half-open connections). Since the server never receives the final ACK, it keeps resources allocated, eventually exhausting them and denying service to legitimate users. Port scanning involves probing multiple ports, not flooding one. ARP poisoning manipulates MAC-to-IP mappings locally. A smurf attack uses ICMP echo requests.

  3. Question 3

    A retail company is upgrading its in-store Wi-Fi network. The security team has mandated the use of the most current and secure wireless encryption protocol available to protect customer data. Which protocol should the network technician implement?

    Answer and explanation

    Correct answer: D

    WPA3 is the latest and most secure wireless security protocol. It replaces the Pre-Shared Key (PSK) exchange in WPA2 with Simultaneous Authentication of Equals (SAE), making it resistant to offline dictionary attacks. WEP and WPA are deprecated and highly insecure. WPA2 is still common but WPA3 offers superior security features and is the correct choice for a new, secure implementation.

  4. Question 4

    Multiple answers

    During a forensic investigation of a compromised web server, a digital forensics specialist creates a bit-for-bit copy of the server's hard drive. To ensure the integrity of this copy, the specialist calculates a unique value for both the original drive and the image file. What is this value called, and which of the following algorithms is commonly used to generate it? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    The value is a cryptographic hash, which serves as a digital fingerprint to verify data integrity. SHA-256 is a widely used and secure hashing algorithm for this purpose.

    SHA-256 is a standard hashing algorithm used in digital forensics to create a unique hash value for evidence, ensuring its integrity throughout the investigation.

  5. Question 5

    A software development team is building a new e-commerce application. The security team mandates that all sensitive data, such as credit card numbers, must be protected while stored in the database. The same key will be used for both encrypting and decrypting this data. Which type of cryptography should be implemented?

    Answer and explanation

    Correct answer: B

    Symmetric encryption uses a single, shared key for both encryption and decryption. It is fast and efficient, making it ideal for encrypting large amounts of data at rest, such as data in a database. Asymmetric encryption uses a key pair (public and private) and is typically used for key exchange and digital signatures. Hashing is a one-way function and cannot be used for decryption. Steganography is the practice of hiding data within other data.

  6. Question 6

    A developer is writing code for a web application's login page. To prevent a common web vulnerability, the developer ensures that the application's response to a failed login attempt is identical whether the username is valid or invalid. Which specific attack is this practice designed to mitigate?

    Answer and explanation

    Correct answer: C

    This practice mitigates username enumeration (or user enumeration). If an application responds differently to an invalid username ('User not found') versus an invalid password ('Incorrect password'), an attacker can use this difference to build a list of valid usernames. By providing a generic error message ('Invalid username or password') in all failure cases, the application prevents attackers from discovering valid user accounts.

  7. Question 7

    True or False: In a cloud Infrastructure as a Service (IaaS) model, the cloud provider is responsible for patching the operating systems of the virtual machines deployed by the customer.

    Answer and explanation

    Correct answer: B

    This statement is false. According to the shared responsibility model for IaaS, the cloud provider is responsible for the security of the cloud (i.e., the physical infrastructure, virtualization layer). The customer is responsible for security in the cloud, which includes securing and patching the guest operating systems, applications, and data they deploy on the infrastructure.

  8. Question 8

    A security analyst is reviewing firewall logs and notices a large volume of inbound traffic from a known malicious IP address has been blocked. The firewall rule that blocked the traffic was automatically created earlier that day. Which security technology MOST likely provided the threat data and instructed the firewall to create the rule?

    Answer and explanation

    Correct answer: B

    A Threat Intelligence Platform (TIP) aggregates, correlates, and analyzes threat data from multiple sources. Modern TIPs can integrate with other security tools like firewalls and SIEMs to automate defensive actions, such as automatically creating firewall rules to block newly identified malicious IP addresses. A honeypot is a decoy system. A load balancer distributes traffic. A vulnerability scanner identifies potential weaknesses but does not typically automate firewall rule creation in this manner.

  9. Question 9

    A hospital is deploying a new network of IoT medical devices (infusion pumps) that must communicate with a central server. These devices have limited processing power and do not support enterprise-grade authentication protocols like 802.1X. The security technician needs to secure the wireless network for these devices while preventing unauthorized connections. Which of the following is the most appropriate security measure in this scenario?

    Answer and explanation

    Correct answer: C

    Given that the IoT devices do not support enterprise authentication, using WPA2 or WPA3-Personal with a very strong, complex preshared key is the best available encryption option. To add another layer of security, the network should be on a separate, isolated VLAN, and MAC address filtering should be enabled to only allow the specific medical devices to connect. While MAC filtering can be spoofed, it provides a deterrent and is a valid part of a defense-in-depth strategy for limited-capability devices. Disabling SSID broadcast is a weak security measure (security by obscurity). WPA3-Enterprise is not supported by the devices.

  10. Question 10

    A company's incident response plan is based on the NIST framework. A security analyst has just finished isolating several compromised systems from the network to prevent the spread of a malware infection. According to the NIST incident response lifecycle, what is the IMMEDIATE next phase?

    Answer and explanation

    Correct answer: C

    The act of isolating compromised systems is part of the Containment phase. According to the NIST incident response lifecycle (Preparation -> Detection & Analysis -> Containment -> Eradication & Recovery -> Post-Incident Activity), the phase immediately following Containment is Eradication & Recovery. This is where the analyst would remove the malware, patch vulnerabilities, and restore the systems to normal operation.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 248 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon