← All CCST Flashcard Decks

Mixed Deck — All CCST Topics Flashcards

100 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CCST Topics flashcards as text
  1. What is Secure Boot and what does it protect against?

    Answer: A UEFI feature that verifies digital signatures of boot software to prevent unauthorized code

    Secure Boot checks digital signatures of bootloader, kernel, and drivers during startup, preventing bootkits and rootkits.

  2. Which layer of the TCP/IP model is responsible for logical addressing and determining the best path for data to travel across the network?

    Answer: Internet

    The Internet layer of the TCP/IP model is responsible for logical addressing (using IP addresses) and routing, which involves selecting the best path for data to travel from the source to the destination network. This layer directly corresponds to the Network Layer of the OSI model.

  3. What is the function of a host-based intrusion detection system (HIDS)?

    Answer: To monitor system activities and file changes to detect intrusion or policy violations

    HIDS monitors file integrity, registry changes, log entries, and process activity to detect unauthorized modifications.

  4. What is the purpose of STP (Spanning Tree Protocol) in a switched network?

    Answer: Prevent broadcast storms by blocking redundant switch paths

    STP prevents Layer 2 switching loops by placing redundant paths in a blocking state, allowing only one active path at a time.

  5. A company's web server crashes and customers cannot access the online store. Which CIA principle is violated?

    Answer: Availability

    Availability ensures systems are accessible when needed. A server crash preventing access violates this.

  6. What advantage does IPv6 provide regarding IPsec support?

    Answer: IPsec is a mandatory part of the IPv6 specification while optional in IPv4

    IPsec was built into the IPv6 specification from the beginning, while it is optional for IPv4.

  7. Which CIA triad component ensures that data has not been altered without authorization?

    Answer: Integrity

    Integrity ensures data remains accurate and unmodified by unauthorized parties.

  8. What is the difference between TIA-568A and TIA-568B wiring standards?

    Answer: They specify different pin-to-wire color assignments for RJ-45, with 568B more common commercially

    Both define different color code arrangements for RJ-45 connectors; 568B is more widely used commercially.

  9. A network administrator needs subnets from 192.168.5.0/24 that each support exactly 14 usable hosts. Which subnet mask should be used?

    Answer: /28

    A /28 subnet has 4 host bits, providing 2^4-2=14 usable host addresses, which exactly meets the requirement.

  10. A company's primary web server goes offline due to a hardware failure. However, an automated system immediately redirects all incoming traffic to a secondary, identical server with no noticeable interruption to users. This setup is a direct implementation of which security principle?

    Answer: Availability

    Availability ensures that systems and data are accessible to authorized users when needed. Using a redundant or failover server is a key strategy for maintaining high availability.

  11. What are the four common light indicators on network devices?

    Answer: Green, operating correctly; green flashing, passing traffic; yellow, connecting or malfunctioned; red, malfunctioned

    Network device indicator lights provide quick visual status cues. Green typically signifies that the device or port is operating correctly, while flashing green indicates active data transmission. Yellow often suggests a transitional state like connecting or a minor issue, and red usually signals a critical malfunction or error.

  12. What is the maximum cable length for Cat 6a Ethernet before signal degradation?

    Answer: 100 meters

    Cat 6a supports 100 meters at full 10 Gbps, the same limit as Cat 5e and Cat 6.

  13. A junior support technician is asked to explain the difference between a vulnerability assessment and a penetration test. Which statement would be the most accurate explanation?

    Answer: A vulnerability assessment finds weaknesses, while a penetration test actively tries to exploit them.

    The key difference is in the approach. A vulnerability assessment is a broad, often automated process that scans for and lists potential weaknesses. A penetration test is a more focused, hands-on process that goes a step further by attempting to actively exploit identified vulnerabilities to determine the real-world impact.

  14. What is the primary function of a default gateway in a host's IP configuration?

    Answer: To provide a path for traffic destined for hosts on remote networks

    The default gateway is the IP address of a router on the same local network as the host. When the host needs to send a packet to an IP address that is not on its local subnet, it sends the packet to the default gateway. The gateway router is then responsible for forwarding the packet toward its final destination.

  15. What type of IPv6 address begins with fe80::/10 and is used for single-segment communication?

    Answer: Link-local

    Link-local addresses (fe80::/10) are auto-assigned and limited to the local network segment, not routable beyond it.

  16. A technician configures a switch port to carry traffic for multiple VLANs between switches. What type of port configuration is this?

    Answer: Trunk port

    A trunk port carries tagged traffic for multiple VLANs between switches or between a switch and a router using IEEE 802.1Q tagging.

  17. What is the purpose of asset inventory in vulnerability management?

    Answer: To maintain a complete record of all systems so vulnerabilities can be identified across the entire environment

    Asset inventory ensures all hardware, software, and services are known so nothing is missed during scanning.

  18. Which type of cable consists of pairs of insulated copper wires twisted together to help protect against signal interference from adjacent pairs?

    Answer: Twisted-pair cable

    Twisted-pair cable, used for Ethernet and telephone communications, has two conductors of a single circuit twisted together. This design helps to cancel out electromagnetic interference (EMI) from external sources and reduce crosstalk between neighboring pairs.

  19. What is the main weakness of WPA2-Personal that WPA3 addresses?

    Answer: The PSK four-way handshake is vulnerable to offline dictionary attacks

    The captured four-way handshake can be brute-forced offline. WPA3's SAE eliminates this vulnerability.

  20. Which protocol allows routers to exchange routing information automatically and is classified as a dynamic routing protocol?

    Answer: OSPF

    OSPF (Open Shortest Path First) is a link-state dynamic routing protocol that routers use to automatically learn and share network routes.