About the Exam

This 90-minute exam covers threat hunting and defending using Cisco security technologies, including threat modeling, threat actor attribution, hunting techniques, hunting processes, and hunting outcomes. It is aimed at candidates pursuing Cisco's Cybersecurity Professional path. Passing it earns the Cisco Certified Specialist - Threat Hunting and Defending certification and satisfies a concentration requirement for the Cybersecurity Professional certification.

Exam Topics

  • Threat Hunting Fundamentals20%
  • Threat Modeling Techniques10%
  • Threat Actor Attribution Techniques20%
  • Threat Hunting Techniques20%
  • Threat Hunting Processes20%
  • Threat Hunting Outcomes10%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated March 25, 2026 at 1:17 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Threat Hunting Fundamentals

How does integrating multiple products improve data visibility and analysis within a corporate environment?

Explanation

A central data visualization tool integrated with product APIs can collect and correlate inputs from multiple systems, providing unified visibility and more effective analysis.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Threat Actor Attribution Techniques

An analyst receives a report stating that the infection chain starts with a phishing email containing a malicious download link. When the victim downloads the malicious RAR file, the archive requires a specific password for extraction, revealing a fake PDF executable malware file and an image printing file. After the malware is decrypted and the fake PDF executable is run, the embedded LummaC2 or Rhadamanthys information stealer executes automatically, collects the victim’s credentials and data, and sends them to the C2 server.

Which conclusion should the analyst make about the threat actor?

Explanation

The activity is a multi-stage intrusion: a phishing link delivers a password-protected archive and disguised executable, which helps bypass security inspection before executing an information stealer. The payload collects credentials and data and transmits them to a command-and-control server, establishing sensitive-information exfiltration as the operation’s primary objective. MITRE ATT&CK identifies malicious-link phishing as a method for delivering malware, including Lumma Stealer.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Threat Actor Attribution Techniques

Refer to the exhibit.

Question Image

What distinguishes the procedures used by each APT group?

Explanation

Plink’s -R option creates remote SSH port forwarding, forming an SSH tunnel to the local RDP endpoint. sc.exe \\HFDC01 query queries service information on the named remote server, which is service enumeration. Microsoft documents that sc.exe query obtains and displays service information and that its server parameter identifies a remote server in UNC format.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Threat Hunting Outcomes

A security analyst receives an alert that host A, with the IP address 192.168.5.39, has had a new browser extension installed. While investigating SIEM tool logs, the analyst finds that host A made continuous TCP connections to 1.25.241.8 over TCP port 80. The IP address 1.25.241.8 is categorized as a C2 server.

Which action should the analyst take to mitigate similar connections going forward?

Explanation

A browser extension deny list prevents installation or use of known-unapproved extensions that can establish command-and-control communications. This addresses the likely source of the continuous C2 connections and reduces recurrence of similar browser-extension-based activity.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Threat Hunting Techniques

Refer to the exhibit.

Question Image

A company was recently breached and decided to strengthen its security posture going forward. A security assessment was commissioned specifically to test the weaknesses exploited during the breach. A security analyst reviews server logs to identify activity related to that security assessment.

Which entry indicates a delivery method associated with an authorized assessment?

Explanation

A web crawler requesting a public-facing page is consistent with authorized reconnaissance to gather publicly available information. This activity is nonintrusive compared with executing a shutdown command or attempting unauthorized administrative access.

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Threat Hunting FundamentalsThreat Modeling TechniquesThreat Actor Attribution TechniquesThreat Hunting TechniquesThreat Hunting ProcessesThreat Hunting Outcomes
Know a question that should be here? Contribute to this exam
Back home