Free Practice

Cisco 100-150 Exam Practice Questions - Updated July 2026

Validexamtopics gives you Cisco 100-150 exam questions built directly from the real 100-150 exam question bank, updated July 2026.

Every Cisco 100-150 question comes with a clear explanation, not just an answer key, so you build real understanding instead of memorizing letters. Get it as a downloadable Cisco 100-150 PDF or a timed, interactive Certified Support Technician (CCST) Networking practice exam.

Cisco 5 Free Questions
0/5 answered
1
Question 1 of 5

An attacker sends an email impersonating the IT department asking a user to reset their password via a fake link. Which type of attack is this?

A
Spear phishing
B
SQL injection
C
DNS amplification
D
Man-in-the-middle
Correct Answer: A

Spear phishing is a targeted email-based social-engineering attack where the attacker impersonates a trusted source to trick the victim into revealing credentials or installing malware. SQL injection targets databases, DNS amplification is a reflection DDoS, and MITM intercepts traffic between two parties.

2
Question 2 of 5

Which symmetric encryption algorithm is currently recommended by NIST for protecting sensitive government data?

A
AES-256
B
DES
C
RC4
D
MD5
Correct Answer: A

AES-256 is the recommended symmetric encryption algorithm for protecting sensitive data. DES is deprecated (56-bit key), RC4 is broken, and MD5 is a hashing algorithm, not encryption.

3
Question 3 of 5

What is the primary purpose of a network firewall's default-deny rule at the end of an access control list?

A
To log all traffic
B
To explicitly drop any traffic not matched by previous allow rules
C
To speed up packet processing
D
To balance load across multiple links
Correct Answer: B

A default-deny (implicit deny) rule at the end of an ACL ensures that any traffic not explicitly allowed by prior rules is dropped. This is a foundational principle of least-privilege network security.

4
Question 4 of 5

Which authentication factor is represented by a hardware token that generates a one-time password every 30 seconds?

A
Something you know
B
Something you have
C
Something you are
D
Somewhere you are
Correct Answer: B

A hardware token is 'something you have' - a possession factor. 'Something you know' is a password/PIN, 'something you are' is a biometric, and 'somewhere you are' is a location factor.

5
Question 5 of 5

During incident response, which phase follows 'Containment' in the standard SANS/NIST lifecycle?

A
Identification
B
Eradication
C
Lessons learned
D
Preparation
Correct Answer: B

The SANS/NIST incident response lifecycle is: Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned. Eradication removes the threat (e.g., malware, backdoors) after the incident has been contained.

Ready for the full question bank?

Access 40+ verified questions with detailed explanations for 100-150.

Browse All Exams