CCST-C logo
Focused certification exam prep
Start practice

CCST-C Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • Exam 100-160 is listed by Cisco as 50 minutes long with a USD 125 fee.
  • Five official domains cover principles, network security, endpoints, vulnerability and risk, and incident handling.
  • Cisco has not published domain percentage weights, so cover all five domains rather than gambling on one.
  • Incident handling questions draw on NIST SP 800-61 lifecycle stages, so learn the phase order cold.

Exam Snapshot: The Facts That Never Change

This cheat sheet is built for the Cisco Certified Support Technician - Cybersecurity exam, code 100-160. Read this section first, because it settles the logistics so the rest of your review can focus on content. If you want the full learning plan behind this one-pager, the CCST-C Study Guide 2026: How to Pass on Your First Attempt walks through it step by step.

ItemWhat Cisco Lists
CertificationCisco Certified Support Technician - Cybersecurity
Exam code100-160
Duration50 minutes
FeeUSD 125
DeliveryScheduled through Pearson VUE (Certiport listing for Cisco CCST)
Official objectivesFive domains, published in the CCST Cybersecurity Exam Objectives document
Domain weightsNot published as official percentages
Question count and passing scoreNot established in official source material; check Cisco's exam page before test day
Read the Prerequisite Language Carefully: The objectives document describes successful candidates as having roughly 150 hours of instruction and hands-on experience. That describes the expected preparation of a typical candidate. It is not presented as a mandatory gate to sit the exam. For a deeper look at who can register, see CCST-C Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Because Cisco has not published weights, treat the five domains as equally likely to appear. A candidate who skips Domain 4 because it "looks small" is taking a risk the official documents do not justify. For the broader breakdown of what each area contains, the CCST-C Exam Domains 2026: Complete Guide to All 5 Content Areas goes further than a one-pager can.

Domain 1: Essential Security Principles

This is the vocabulary and theory foundation. Questions here tend to test whether you can tell similar terms apart and match a scenario to the correct concept.

Core Definitions

Know these cold and be able to distinguish them in a scenario.

  • Vulnerability, threat, exploit, risk: a weakness, something that could use it, the method that uses it, and the likelihood and impact of that happening.
  • Attack vector: the path an attacker uses to reach a target.
  • Hardening and defense-in-depth: reducing attack surface on a system, and layering controls so no single failure is fatal.
  • CIA triad: confidentiality, integrity, availability. Practice mapping each control or attack to the property it affects.
  • Attacker types, motives and the code of ethics are all fair game.

Threats You Must Recognize on Sight

Expect scenario wording that describes behavior without naming the attack.

  • Malware, ransomware, denial of service and botnets
  • Social engineering: tailgating (physical), phishing (broad email), spear phishing (targeted email), vishing (voice) and smishing (SMS)
  • Physical attacks, man in the middle, IoT vulnerabilities
  • Insider threats and Advanced Persistent Threats (APT), where the key idea is a long-term, stealthy campaign

Access Management and Encryption

Two clusters that reward precise definitions.

  • AAA: authentication (who are you), authorization (what may you do), accounting (what did you do). Know RADIUS as a common AAA protocol.
  • MFA and password policies: combining factor types, and what makes a policy strong.
  • Encryption types, hashing, certificates and PKI: hashing is one-way and supports integrity; encryption is reversible with a key.
  • Strong versus weak algorithms and the three data states: in transit, at rest and in use. Know which protocols provide encryption on the wire.

Domain 2: Basic Network Security Concepts

This domain assumes you can think like a network technician and then ask "how does this break?" It overlaps with CCST Networking knowledge, but the angle is always security.

Protocol Weaknesses

The objectives name TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS. For each one, pair the protocol with its signature weakness. ARP has no authentication, which enables spoofing. DHCP can be abused by rogue servers. DNS can be poisoned or abused for redirection. HTTP sends content in the clear. ICMP can be used for reconnaissance and flooding.

Addressing and Segmentation

  • IPv4 and IPv6 addresses, MAC addresses, and why each matters for tracking and filtering
  • Network segmentation as a containment strategy
  • CIDR notation, NAT, and public versus private networks

Architecture, Wireless and Secure Access

  • Infrastructure concepts: network security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS and IPS. Remember that an IDS detects and alerts while an IPS can block inline.
  • Secure SoHo wireless: MAC address filtering, encryption standards and protocols, and SSID settings. Know that MAC filtering and hiding an SSID are weak controls compared with strong encryption.
  • Secure access technologies: ACL, firewall, VPN and NAC.
Why Wireless Gets Special Attention: Setting up a secure wireless SoHo network is an explicit objective, which signals that candidates should be comfortable with practical configuration choices, not just definitions. Be ready to pick the strongest combination of settings from a list.

Domain 3: Endpoint Security Concepts

Domain 3 is the most hands-on territory in the blueprint. It spans operating systems, tools, compliance, patching, logs and malware cleanup.

Operating System Security

Windows, macOS and Linux each have native protections.

  • Windows Defender and host-based firewalls
  • Command line fluency, including CLI and PowerShell
  • File and directory permissions, and how privilege escalation abuses weak ones

Assessment Tools

The objectives name three commands specifically.

  • netstat: view active connections and listening ports
  • nslookup: query DNS records and check name resolution
  • tcpdump: capture and inspect packets from the command line

Policy, Compliance and Updates

Verifying that endpoints meet standards is its own objective.

  • Hardware and software inventory, asset management, program deployment and configuration management
  • Data backups and data encryption, plus BYOD device management and app distribution
  • Regulatory frameworks named in the objectives: PCI DSS, HIPAA and GDPR
  • Updates: Windows Update, application updates, device drivers, firmware and patching

Logs and Malware Removal

Reading evidence and cleaning up afterward.

  • Event Viewer, audit logs, system and application logs, syslog, and spotting anomalies
  • Malware removal: scanning systems, reviewing scan logs and remediation

If the hands-on portions worry you, read How Hard Is the CCST-C Exam? Complete Difficulty Guide 2026 for a realistic view of which areas candidates tend to find tougher.

Domain 4: Vulnerability Assessment and Risk Management

This domain shifts from "what is it" to "what do you do about it." Questions often ask you to choose the next sensible action.

Vulnerability Management and Threat Intelligence

  • Identification, management and mitigation of vulnerabilities
  • Active versus passive reconnaissance, and testing such as port scanning and automation
  • Vulnerability databases and Common Vulnerabilities and Exposures (CVEs), including their uses and limitations
  • Intelligence sources: cybersecurity reports and news, subscription services, collective intelligence, and ad hoc versus automated threat intelligence
  • Documentation: keeping it updated and sharing it securely before, during and after an incident

Risk Management

Learn the distinction between a vulnerability and a risk: a vulnerability is a weakness, while risk combines likelihood and impact. Review how risks are ranked and assigned levels, the general approaches to handling risk, mitigation strategies, data classification risks, and security assessments of IT systems.

Disaster Recovery and Business Continuity

Know the difference in purpose between a disaster recovery plan (restoring systems and data) and a business continuity plan (keeping the organization operating). Expect to separate natural from human-caused disasters and to recognize backup and recovery controls.

Key Takeaway

When a Domain 4 question describes a finding, ask two things in order: how severe is it given the asset's data classification, and what is the most proportionate mitigation? Answers that jump straight to the most extreme control are usually wrong.

Domain 5: Incident Handling

The final domain connects monitoring, investigation, compliance and response into one workflow.

Monitoring and Escalation

Recognize suspicious activity and know when to hand it up.

  • The role of SIEM (aggregating and correlating events) and SOAR (automating response)
  • Monitoring network data, packet captures and log file entries to identify suspicious events

Forensics and Attribution

Frameworks and evidence handling.

  • Cyber Kill Chain, MITRE ATT&CK Matrix and the Diamond Model
  • Tactics, Techniques and Procedures (TTP)
  • Sources of evidence, artifacts, evidence preservation and chain of custody

Compliance and Response Lifecycle

Reporting duties and the formal process.

  • How GDPR, HIPAA, PCI-DSS, FERPA and FISMA affect reporting and notification requirements
  • Incident response policies, plans and procedures
  • The incident response lifecycle stages drawn from NIST Special Publication 800-61 (sections 2.3 and 3.1 through 3.4)
Memorize the Lifecycle in Order: The NIST 800-61 lifecycle is a sequence, and questions frequently test which step comes next or which activity belongs to which phase. Be able to place preparation, detection and analysis, containment, eradication and recovery, and post-incident activity correctly, and to explain what happens in each.

Confusable Pairs Worth Memorizing

Cybersecurity entry-level exams love near-synonyms. This table pairs the terms the CCST Cybersecurity objectives put side by side, so you can drill the distinctions quickly.

PairHow They Differ
Phishing vs. spear phishingBroad mass email versus a message crafted for a specific target
Vishing vs. smishingVoice call versus text message
Authentication vs. authorizationProving identity versus determining permitted actions
Hashing vs. encryptionOne-way integrity check versus reversible confidentiality
IDS vs. IPSDetects and alerts versus can block traffic inline
Vulnerability vs. riskA weakness versus the likelihood and impact of its exploitation
Active vs. passive reconnaissanceDirectly probing a target versus observing without touching it
DRP vs. BCPRestoring systems and data versus sustaining business operations
SIEM vs. SOARCorrelating and alerting on events versus orchestrating automated response
Data in transit vs. at rest vs. in useMoving across a network, stored on media, or actively being processed

Scheduling Your Review by Domain

Since official weights are unpublished, a balanced schedule makes sense. Place the conceptual domains first because later domains reuse their vocabulary, and finish with incident handling because it synthesizes everything else.

Week 1

Domain 1: Principles

  • Lock down definitions, CIA mapping and the social engineering variants
  • Drill AAA, MFA, hashing, PKI and the three data states
Week 2

Domain 2: Network Security

  • Pair each protocol with its weakness
  • Practice CIDR, NAT and segmentation, then secure SoHo wireless choices
Week 3

Domain 3: Endpoints

  • Run netstat, nslookup and tcpdump yourself rather than only reading about them
  • Review patching, logs, compliance frameworks and malware remediation steps
Week 4

Domains 4 and 5, then full review

  • Cover risk ranking, DRP versus BCP, SIEM and SOAR, forensics frameworks and the NIST lifecycle
  • Finish with timed practice at the 50-minute pace

Adjust the pacing to your background. A candidate with networking experience can compress Week 2, while someone newer to IT may want to double the endpoint week. Timed practice matters because the exam is only 50 minutes; you can sharpen that pacing with the question sets on the CCST-C practice test site.

Where This Credential Fits in Your Career

CCST Cybersecurity is positioned as an entry-level credential. The domains map naturally to the day-to-day work of help desk, IT support and junior security roles: reading logs, applying patches, checking endpoint compliance, escalating suspicious events and following an incident response plan. Employers looking for support technicians with security awareness are the natural audience. For a closer look at the job landscape, see CCST-C Jobs, and for money-related questions, review the CCST-C Salary Guide 2026: Complete Earnings Analysis and Is the CCST-C Certification Worth It? Complete ROI Analysis 2026.

Don't Confuse the Neighbors: CCST Cybersecurity is distinct from CCST Networking and from Cisco CyberOps Associate. CCST Networking centers on network fundamentals, while CyberOps Associate sits at a deeper security-operations level. Make sure the exam you book is 100-160, and verify the current details on Cisco's official page and the Pearson VUE listing before paying.

Before registering, confirm the live fee and scheduling process, and compare it against your budget using the CCST-C Certification Cost 2026: Complete Pricing Breakdown. When you are ready to test yourself against realistic questions, the main practice test hub is the fastest way to find your weak domains.

Frequently Asked Questions

How long is the CCST Cybersecurity exam and what does it cost?

Cisco lists exam 100-160 at 50 minutes with a fee of USD 125. Always confirm the current figures on Cisco's official exam page and the Pearson VUE listing, since pricing and policies can change.

What are the five domains on the exam?

They are Essential Security Principles, Basic Network Security Concepts, Endpoint Security Concepts, Vulnerability Assessment and Risk Management, and Incident Handling. Cisco publishes the objectives for each but has not released official percentage weights.

Do I need 150 hours of experience before I can sit the exam?

The objectives describe a successful candidate as having about 150 hours of instruction and hands-on experience. That is a description of expected preparation, not a stated mandatory prerequisite. See the requirements article for full eligibility details.

What is the passing score?

A numeric passing score and question count were not established in the official source material this cheat sheet relies on, so check Cisco's exam page for current information rather than trusting unofficial figures. The CCST-C Passing Score 2026 article covers what is and is not known.

Which commands and frameworks should I know by name?

For commands, know netstat, nslookup and tcpdump. For frameworks and standards, know the Cyber Kill Chain, MITRE ATT&CK Matrix, the Diamond Model, and the NIST SP 800-61 incident response lifecycle. Also recognize compliance regimes such as GDPR, HIPAA, PCI DSS, FERPA and FISMA.

Ready to pass your CCST-C exam?

Put this into practice with free CCST-C questions across every exam domain.