Oklahoma Cybersecurity Technical
Support Specialist Assessment Exam
Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2027 Q&A| Instant
Download Pdf.
1. A cybersecurity technical support specialist is investigating a
workstation that suddenly begins making repeated outbound
connections to an unfamiliar external IP address. The user reports
no intentional changes to the system. Which action should the
specialist take FIRST to preserve security while minimizing
unnecessary disruption to potential evidence?
A. Immediately delete all suspicious files from the workstation
B. Disconnect the workstation from the network while preserving the
system state for investigation
C. Reinstall the operating system before collecting any information
D. Ask the user to continue working normally so additional activity can be
observed
,Answer: B. Disconnect the workstation from the network while
preserving the system state for investigation.
Rationale: Isolating a potentially compromised workstation limits
further communication with an attacker or malicious infrastructure
while helping preserve evidence that can be examined during incident
response.
2. Which principle requires a user to receive only the permissions
necessary to perform assigned job duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Security through obscurity
Answer: C. Least privilege.
Rationale: The principle of least privilege limits accounts and processes
to the minimum permissions required, reducing the potential damage
caused by mistakes, compromised credentials, or malicious activity.
3. A support specialist receives an email appearing to come from the
organization's IT department requesting that the employee
immediately provide a password through a linked website. Which
characteristic most strongly indicates phishing?
A. The message contains the employee's correct name
B. The message requests sensitive information through an unsolicited link
,C. The message uses the organization's standard email signature
D. The message arrives during normal business hours
Answer: B. The message requests sensitive information through an
unsolicited link.
Rationale: Phishing commonly uses deceptive messages and links to
persuade recipients to disclose credentials or other sensitive
information.
4. Which technology is primarily responsible for translating a human-
readable domain name such as example.com into an IP address?
A. DHCP
B. DNS
C. FTP
D. SNMP
Answer: B. DNS.
Rationale: The Domain Name System translates domain names into IP
addresses and performs related name-resolution functions required for
network communication.
5. A workstation has an IP address of 192.168.10.25 with a subnet
mask of 255.255.255.0. Which address identifies the network?
A. 192.168.10.0
B. 192.168.10.1
, C. 192.168.10.25
D. 192.168.255.0
Answer: A. 192.168.10.0.
Rationale: A 255.255.255.0 mask corresponds to a /24 network, making
the first three octets the network portion and 192.168.10.0 the network
address.
6. Which command-line utility is commonly used to test basic IP
connectivity between a source system and a destination host?
A. ping
B. format
C. chmod
D. taskkill
Answer: A. ping.
Rationale: The ping utility sends ICMP echo requests and evaluates
responses to determine whether an IP destination is reachable and to
measure basic network latency.
7. A technician needs to determine the path packets take from a
workstation to a remote server. Which tool is most appropriate?
A. traceroute or tracert
B. ipconfig only
Support Specialist Assessment Exam
Practice Questions And Correct
Answers (Verified Answers) Plus
Rationale 2027 Q&A| Instant
Download Pdf.
1. A cybersecurity technical support specialist is investigating a
workstation that suddenly begins making repeated outbound
connections to an unfamiliar external IP address. The user reports
no intentional changes to the system. Which action should the
specialist take FIRST to preserve security while minimizing
unnecessary disruption to potential evidence?
A. Immediately delete all suspicious files from the workstation
B. Disconnect the workstation from the network while preserving the
system state for investigation
C. Reinstall the operating system before collecting any information
D. Ask the user to continue working normally so additional activity can be
observed
,Answer: B. Disconnect the workstation from the network while
preserving the system state for investigation.
Rationale: Isolating a potentially compromised workstation limits
further communication with an attacker or malicious infrastructure
while helping preserve evidence that can be examined during incident
response.
2. Which principle requires a user to receive only the permissions
necessary to perform assigned job duties?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Security through obscurity
Answer: C. Least privilege.
Rationale: The principle of least privilege limits accounts and processes
to the minimum permissions required, reducing the potential damage
caused by mistakes, compromised credentials, or malicious activity.
3. A support specialist receives an email appearing to come from the
organization's IT department requesting that the employee
immediately provide a password through a linked website. Which
characteristic most strongly indicates phishing?
A. The message contains the employee's correct name
B. The message requests sensitive information through an unsolicited link
,C. The message uses the organization's standard email signature
D. The message arrives during normal business hours
Answer: B. The message requests sensitive information through an
unsolicited link.
Rationale: Phishing commonly uses deceptive messages and links to
persuade recipients to disclose credentials or other sensitive
information.
4. Which technology is primarily responsible for translating a human-
readable domain name such as example.com into an IP address?
A. DHCP
B. DNS
C. FTP
D. SNMP
Answer: B. DNS.
Rationale: The Domain Name System translates domain names into IP
addresses and performs related name-resolution functions required for
network communication.
5. A workstation has an IP address of 192.168.10.25 with a subnet
mask of 255.255.255.0. Which address identifies the network?
A. 192.168.10.0
B. 192.168.10.1
, C. 192.168.10.25
D. 192.168.255.0
Answer: A. 192.168.10.0.
Rationale: A 255.255.255.0 mask corresponds to a /24 network, making
the first three octets the network portion and 192.168.10.0 the network
address.
6. Which command-line utility is commonly used to test basic IP
connectivity between a source system and a destination host?
A. ping
B. format
C. chmod
D. taskkill
Answer: A. ping.
Rationale: The ping utility sends ICMP echo requests and evaluates
responses to determine whether an IP destination is reachable and to
measure basic network latency.
7. A technician needs to determine the path packets take from a
workstation to a remote server. Which tool is most appropriate?
A. traceroute or tracert
B. ipconfig only