Skip to exam content
← All Exams
Techclick Infosec

Cisco 100-160 Practice Test

Security Principles · Network Security · Endpoint Security · Vulnerability & Risk · Incident Handling

52 questions · 75 min · 70% Techclick practice target

52
Questions
75
Minutes
70%
Techclick Practice Target

⚠️ Exam Rules

  • Once started, the timer cannot be paused
  • You can navigate freely — use Previous or the Navigator panel to revisit any question
  • Tab-switching triggers warnings (3 strikes = auto-submit)
  • Right-click and copy disabled during exam
  • If you fail, retry — questions and options reshuffle

100-160 practice test: what's covered

Questions in this Techclick bank52
Timer75 min
Techclick practice target70%
Official exam code100-160

Free 100-160 sample questions

  1. A hospital's patient-records database is online and reachable, and the records have not been altered, but a contractor with no clinical role was able to read a patient chart. Which element of the CIA triad has been broken?

    • A. Confidentiality, because the data was disclosed to someone with no need to know
    • B. Integrity, because the contractor interacted with a production clinical record
    • C. Availability, because an unauthorised session consumed database resources
    • D. Non-repudiation, because the contractor can deny opening the patient chart
    Show answer

    Correct: A. Confidentiality means only authorised parties can read data, so unauthorised disclosure breaks it. Integrity is wrong because nothing was altered — reading is not modification. Availability is wrong because the system stayed reachable and performant. Non-repudiation concerns proof of action, not disclosure, so it is not the element violated here.

  2. A junior technician is granted domain administrator rights so they can occasionally reset user passwords. A security reviewer flags the arrangement. Which principle is the reviewer applying?

    • A. Least privilege — grant only the rights the role actually requires
    • B. Defence in depth — place several controls in the path of an attacker
    • C. Separation of duties — split a sensitive task between two people
    • D. Implicit deny — block anything a rule does not explicitly permit
    Show answer

    Correct: A. Least privilege says an account gets the minimum rights needed for its job; a password-reset role needs a delegated helpdesk right, not full domain admin. Defence in depth is about layering controls, not sizing permissions. Separation of duties splits one task across people and is not what is wrong here. Implicit deny is a firewall or ACL default, not an account-rights principle.

  3. An attacker phones a finance clerk, claims to be the CFO travelling abroad, stresses that a vendor payment is overdue, and asks the clerk to release the transfer immediately. Which technique is being used?

    • A. Social engineering using authority and urgency as pressure levers
    • B. A watering-hole attack against a site the clerk visits often
    • C. An on-path attack that intercepts the payment instruction in transit
    • D. Credential stuffing using passwords leaked from another breach
    Show answer

    Correct: A. The attacker manipulates a person, not a machine, using impersonated authority plus time pressure — the classic business email or vishing pattern. A watering-hole attack compromises a website the victim visits, which is not happening. An on-path attack intercepts traffic between two systems. Credential stuffing replays leaked passwords against logins, so none of those three match a phone call.

  4. A small clinic must show that a specific pharmacist, and no one else, approved a controlled-drug order. Which two security services together provide that assurance? (Choose TWO)

    • A. Authentication that reliably proves who the pharmacist is
    • B. Non-repudiation through a digital signature on the approval
    • C. Data availability through nightly replication to a second site
    • D. Bandwidth shaping applied to the pharmacy VLAN
    • E. Full-disk encryption of the pharmacist's workstation
    Show answer

    Correct: A and B. Proving who acted requires authentication, and preventing a later denial of that action requires non-repudiation, normally via a digital signature bound to the approver's private key. Replication supports availability, not attribution. Bandwidth shaping is a performance control. Full-disk encryption protects data at rest on a lost laptop but says nothing about who approved an order.

  5. A retailer stores card data and is preparing for its yearly assessment. Which framework specifically governs how that cardholder data must be protected?

    • A. PCI DSS, the payment card industry data security standard
    • B. HIPAA, which governs protected health information
    • C. GDPR, which governs EU personal data processing broadly
    • D. SOX, which governs financial reporting controls
    Show answer

    Correct: A. PCI DSS is the card-brand standard that sets controls for storing, processing and transmitting cardholder data. HIPAA is wrong because it covers health information, not payment cards. GDPR covers personal data of EU residents generally and does not define card-storage controls. SOX targets the integrity of financial reporting, not cardholder data handling.

Last updated:

100-160 practice test FAQ

Is this 100-160 practice test free?

Yes. You can start, finish and score it for free, and download the Techclick practice certificate.

How many questions are in the Techclick 100-160 practice test?

This bank has 52 original scenario-based questions with a 75-minute timer and a 70% Techclick practice target.

What is the official exam code and format?

The official exam code is 100-160 (Cisco).

Are these real 100-160 exam questions or dumps?

No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.

Do I get a certificate?

Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Cisco certification.

What should I take after 100-160?

Related practice tests: CCIE Security Written 350-701, CCNA 200-301, Cisco 300-410, CCNP ENCOR 350-401, Cisco 200-201, Cisco 350-201 (linked below).

Techclick Infosec
TECHCLICK INFOSEC
CYBERSECURITY · PRACTICE ASSESSMENT
🛡️
PRACTICE ASSESSMENT
Cisco CCST Cyber
Security Principles · Network Security · Endpoint Security · Vulnerability & Risk · Incident Handling
AWARDED TO
{NAME}
SCORE
0%
DATE
--
TC-100-160-XXX
Verified at exam.techclick.in · Techclick Infosec Pvt Ltd · +91 92772 29456
✕Exhibit (zoomed)