Security Principles · Network Security · Endpoint Security · Vulnerability & Risk · Incident Handling
52 questions · 75 min · 70% Techclick practice target
⚠️ Exam Rules
| Questions in this Techclick bank | 52 |
|---|---|
| Timer | 75 min |
| Techclick practice target | 70% |
| Official exam code | 100-160 |
A hospital's patient-records database is online and reachable, and the records have not been altered, but a contractor with no clinical role was able to read a patient chart. Which element of the CIA triad has been broken?
Correct: A. Confidentiality means only authorised parties can read data, so unauthorised disclosure breaks it. Integrity is wrong because nothing was altered — reading is not modification. Availability is wrong because the system stayed reachable and performant. Non-repudiation concerns proof of action, not disclosure, so it is not the element violated here.
A junior technician is granted domain administrator rights so they can occasionally reset user passwords. A security reviewer flags the arrangement. Which principle is the reviewer applying?
Correct: A. Least privilege says an account gets the minimum rights needed for its job; a password-reset role needs a delegated helpdesk right, not full domain admin. Defence in depth is about layering controls, not sizing permissions. Separation of duties splits one task across people and is not what is wrong here. Implicit deny is a firewall or ACL default, not an account-rights principle.
An attacker phones a finance clerk, claims to be the CFO travelling abroad, stresses that a vendor payment is overdue, and asks the clerk to release the transfer immediately. Which technique is being used?
Correct: A. The attacker manipulates a person, not a machine, using impersonated authority plus time pressure — the classic business email or vishing pattern. A watering-hole attack compromises a website the victim visits, which is not happening. An on-path attack intercepts traffic between two systems. Credential stuffing replays leaked passwords against logins, so none of those three match a phone call.
A small clinic must show that a specific pharmacist, and no one else, approved a controlled-drug order. Which two security services together provide that assurance? (Choose TWO)
Correct: A and B. Proving who acted requires authentication, and preventing a later denial of that action requires non-repudiation, normally via a digital signature bound to the approver's private key. Replication supports availability, not attribution. Bandwidth shaping is a performance control. Full-disk encryption protects data at rest on a lost laptop but says nothing about who approved an order.
A retailer stores card data and is preparing for its yearly assessment. Which framework specifically governs how that cardholder data must be protected?
Correct: A. PCI DSS is the card-brand standard that sets controls for storing, processing and transmitting cardholder data. HIPAA is wrong because it covers health information, not payment cards. GDPR covers personal data of EU residents generally and does not define card-storage controls. SOX targets the integrity of financial reporting, not cardholder data handling.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 52 original scenario-based questions with a 75-minute timer and a 70% Techclick practice target.
The official exam code is 100-160 (Cisco).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official Cisco certification.
Related practice tests: CCIE Security Written 350-701, CCNA 200-301, Cisco 300-410, CCNP ENCOR 350-401, Cisco 200-201, Cisco 350-201 (linked below).

You earned it — let the world know!
