Oklahoma Cybersecurity Technical
Support Specialist Assessment Exam
Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2027 Q&A| Instant
Download Pdf.
1. Which principle of cybersecurity requires an organization to use
multiple, overlapping security controls so that the failure or compromise
of one control does not automatically result in complete system
compromise?
A. Least privilege
B. Defense in depth
C. Single sign-on
D. Data minimization
Defense in depth uses multiple layers of administrative, technical, and
physical controls so that security does not depend on a single protective
mechanism. This approach is a foundational cybersecurity practice
identified for the Oklahoma CareerTech Cybersecurity Technical Support
Specialist assessment.
, 2. A technical support specialist receives an alert indicating that a
workstation has communicated with a known malicious IP address.
What should be the specialist's FIRST priority?
A. Delete the workstation's event logs
B. Immediately reinstall the operating system
C. Follow the organization's incident-response procedure and contain
the potential threat
D. Disable all network security controls
Potential compromise should be handled according to established
incident-response procedures, with containment used to limit further
damage while preserving information needed for investigation.
3. Which security principle states that a user should receive only the
permissions necessary to perform assigned duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Availability
Least privilege limits access rights to the minimum necessary level,
reducing the potential impact of compromised accounts, accidental
actions, and insider threats.
4. An employee receives an email that appears to come from the
organization's payroll department and requests immediate
, confirmation of banking credentials through an unfamiliar website.
Which attack is MOST likely being attempted?
A. Denial-of-service attack
B. Phishing
C. Port scanning
D. Packet fragmentation
Phishing uses deceptive communications to persuade recipients to
disclose credentials, financial information, or other sensitive
information or to perform malicious actions.
5. Which characteristic BEST distinguishes spear phishing from
ordinary phishing?
A. Spear phishing can occur only through telephone calls
B. Spear phishing always uses malware attachments
C. Spear phishing is targeted toward a specific person or organization
using tailored information
D. Spear phishing does not attempt to obtain credentials
Spear phishing is a targeted form of phishing in which the attacker
customizes the communication to increase its credibility and likelihood
of success.
6. Which security objective ensures that authorized users can access
systems and information when they are needed?
, A. Confidentiality
B. Integrity
C. Authentication
D. Availability
Availability is the cybersecurity objective concerned with ensuring that
authorized users have timely and reliable access to systems,
applications, and information.
7. A file containing payroll information is modified without
authorization while remaining accessible to employees. Which
component of the CIA triad has been primarily violated?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Integrity protects information from unauthorized alteration or
destruction, so an unauthorized modification of payroll data represents
an integrity violation.
8. Which situation represents a confidentiality violation?
A. A server becomes unavailable because of a hardware failure
B. An authorized employee corrects an accounting error
C. An unauthorized person obtains access to confidential employee
Support Specialist Assessment Exam
Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2027 Q&A| Instant
Download Pdf.
1. Which principle of cybersecurity requires an organization to use
multiple, overlapping security controls so that the failure or compromise
of one control does not automatically result in complete system
compromise?
A. Least privilege
B. Defense in depth
C. Single sign-on
D. Data minimization
Defense in depth uses multiple layers of administrative, technical, and
physical controls so that security does not depend on a single protective
mechanism. This approach is a foundational cybersecurity practice
identified for the Oklahoma CareerTech Cybersecurity Technical Support
Specialist assessment.
, 2. A technical support specialist receives an alert indicating that a
workstation has communicated with a known malicious IP address.
What should be the specialist's FIRST priority?
A. Delete the workstation's event logs
B. Immediately reinstall the operating system
C. Follow the organization's incident-response procedure and contain
the potential threat
D. Disable all network security controls
Potential compromise should be handled according to established
incident-response procedures, with containment used to limit further
damage while preserving information needed for investigation.
3. Which security principle states that a user should receive only the
permissions necessary to perform assigned duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Availability
Least privilege limits access rights to the minimum necessary level,
reducing the potential impact of compromised accounts, accidental
actions, and insider threats.
4. An employee receives an email that appears to come from the
organization's payroll department and requests immediate
, confirmation of banking credentials through an unfamiliar website.
Which attack is MOST likely being attempted?
A. Denial-of-service attack
B. Phishing
C. Port scanning
D. Packet fragmentation
Phishing uses deceptive communications to persuade recipients to
disclose credentials, financial information, or other sensitive
information or to perform malicious actions.
5. Which characteristic BEST distinguishes spear phishing from
ordinary phishing?
A. Spear phishing can occur only through telephone calls
B. Spear phishing always uses malware attachments
C. Spear phishing is targeted toward a specific person or organization
using tailored information
D. Spear phishing does not attempt to obtain credentials
Spear phishing is a targeted form of phishing in which the attacker
customizes the communication to increase its credibility and likelihood
of success.
6. Which security objective ensures that authorized users can access
systems and information when they are needed?
, A. Confidentiality
B. Integrity
C. Authentication
D. Availability
Availability is the cybersecurity objective concerned with ensuring that
authorized users have timely and reliable access to systems,
applications, and information.
7. A file containing payroll information is modified without
authorization while remaining accessible to employees. Which
component of the CIA triad has been primarily violated?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Integrity protects information from unauthorized alteration or
destruction, so an unauthorized modification of payroll data represents
an integrity violation.
8. Which situation represents a confidentiality violation?
A. A server becomes unavailable because of a hardware failure
B. An authorized employee corrects an accounting error
C. An unauthorized person obtains access to confidential employee