- Exam Snapshot: The Facts That Never Change
- Domain 1: Essential Security Principles
- Domain 2: Basic Network Security Concepts
- Domain 3: Endpoint Security Concepts
- Domain 4: Vulnerability Assessment and Risk Management
- Domain 5: Incident Handling
- Confusable Pairs Worth Memorizing
- Scheduling Your Review by Domain
- Where This Credential Fits in Your Career
- Frequently Asked Questions
- Exam 100-160 is listed by Cisco as 50 minutes long with a USD 125 fee.
- Five official domains cover principles, network security, endpoints, vulnerability and risk, and incident handling.
- Cisco has not published domain percentage weights, so cover all five domains rather than gambling on one.
- Incident handling questions draw on NIST SP 800-61 lifecycle stages, so learn the phase order cold.
Exam Snapshot: The Facts That Never Change
This cheat sheet is built for the Cisco Certified Support Technician - Cybersecurity exam, code 100-160. Read this section first, because it settles the logistics so the rest of your review can focus on content. If you want the full learning plan behind this one-pager, the CCST-C Study Guide 2026: How to Pass on Your First Attempt walks through it step by step.
| Item | What Cisco Lists |
|---|---|
| Certification | Cisco Certified Support Technician - Cybersecurity |
| Exam code | 100-160 |
| Duration | 50 minutes |
| Fee | USD 125 |
| Delivery | Scheduled through Pearson VUE (Certiport listing for Cisco CCST) |
| Official objectives | Five domains, published in the CCST Cybersecurity Exam Objectives document |
| Domain weights | Not published as official percentages |
| Question count and passing score | Not established in official source material; check Cisco's exam page before test day |
Because Cisco has not published weights, treat the five domains as equally likely to appear. A candidate who skips Domain 4 because it "looks small" is taking a risk the official documents do not justify. For the broader breakdown of what each area contains, the CCST-C Exam Domains 2026: Complete Guide to All 5 Content Areas goes further than a one-pager can.
Domain 1: Essential Security Principles
This is the vocabulary and theory foundation. Questions here tend to test whether you can tell similar terms apart and match a scenario to the correct concept.
Core Definitions
Know these cold and be able to distinguish them in a scenario.
- Vulnerability, threat, exploit, risk: a weakness, something that could use it, the method that uses it, and the likelihood and impact of that happening.
- Attack vector: the path an attacker uses to reach a target.
- Hardening and defense-in-depth: reducing attack surface on a system, and layering controls so no single failure is fatal.
- CIA triad: confidentiality, integrity, availability. Practice mapping each control or attack to the property it affects.
- Attacker types, motives and the code of ethics are all fair game.
Threats You Must Recognize on Sight
Expect scenario wording that describes behavior without naming the attack.
- Malware, ransomware, denial of service and botnets
- Social engineering: tailgating (physical), phishing (broad email), spear phishing (targeted email), vishing (voice) and smishing (SMS)
- Physical attacks, man in the middle, IoT vulnerabilities
- Insider threats and Advanced Persistent Threats (APT), where the key idea is a long-term, stealthy campaign
Access Management and Encryption
Two clusters that reward precise definitions.
- AAA: authentication (who are you), authorization (what may you do), accounting (what did you do). Know RADIUS as a common AAA protocol.
- MFA and password policies: combining factor types, and what makes a policy strong.
- Encryption types, hashing, certificates and PKI: hashing is one-way and supports integrity; encryption is reversible with a key.
- Strong versus weak algorithms and the three data states: in transit, at rest and in use. Know which protocols provide encryption on the wire.
Domain 2: Basic Network Security Concepts
This domain assumes you can think like a network technician and then ask "how does this break?" It overlaps with CCST Networking knowledge, but the angle is always security.
Protocol Weaknesses
The objectives name TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS. For each one, pair the protocol with its signature weakness. ARP has no authentication, which enables spoofing. DHCP can be abused by rogue servers. DNS can be poisoned or abused for redirection. HTTP sends content in the clear. ICMP can be used for reconnaissance and flooding.
Addressing and Segmentation
- IPv4 and IPv6 addresses, MAC addresses, and why each matters for tracking and filtering
- Network segmentation as a containment strategy
- CIDR notation, NAT, and public versus private networks
Architecture, Wireless and Secure Access
- Infrastructure concepts: network security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS and IPS. Remember that an IDS detects and alerts while an IPS can block inline.
- Secure SoHo wireless: MAC address filtering, encryption standards and protocols, and SSID settings. Know that MAC filtering and hiding an SSID are weak controls compared with strong encryption.
- Secure access technologies: ACL, firewall, VPN and NAC.
Domain 3: Endpoint Security Concepts
Domain 3 is the most hands-on territory in the blueprint. It spans operating systems, tools, compliance, patching, logs and malware cleanup.
Operating System Security
Windows, macOS and Linux each have native protections.
- Windows Defender and host-based firewalls
- Command line fluency, including CLI and PowerShell
- File and directory permissions, and how privilege escalation abuses weak ones
Assessment Tools
The objectives name three commands specifically.
- netstat: view active connections and listening ports
- nslookup: query DNS records and check name resolution
- tcpdump: capture and inspect packets from the command line
Policy, Compliance and Updates
Verifying that endpoints meet standards is its own objective.
- Hardware and software inventory, asset management, program deployment and configuration management
- Data backups and data encryption, plus BYOD device management and app distribution
- Regulatory frameworks named in the objectives: PCI DSS, HIPAA and GDPR
- Updates: Windows Update, application updates, device drivers, firmware and patching
Logs and Malware Removal
Reading evidence and cleaning up afterward.
- Event Viewer, audit logs, system and application logs, syslog, and spotting anomalies
- Malware removal: scanning systems, reviewing scan logs and remediation
If the hands-on portions worry you, read How Hard Is the CCST-C Exam? Complete Difficulty Guide 2026 for a realistic view of which areas candidates tend to find tougher.
Domain 4: Vulnerability Assessment and Risk Management
This domain shifts from "what is it" to "what do you do about it." Questions often ask you to choose the next sensible action.
Vulnerability Management and Threat Intelligence
- Identification, management and mitigation of vulnerabilities
- Active versus passive reconnaissance, and testing such as port scanning and automation
- Vulnerability databases and Common Vulnerabilities and Exposures (CVEs), including their uses and limitations
- Intelligence sources: cybersecurity reports and news, subscription services, collective intelligence, and ad hoc versus automated threat intelligence
- Documentation: keeping it updated and sharing it securely before, during and after an incident
Risk Management
Learn the distinction between a vulnerability and a risk: a vulnerability is a weakness, while risk combines likelihood and impact. Review how risks are ranked and assigned levels, the general approaches to handling risk, mitigation strategies, data classification risks, and security assessments of IT systems.
Disaster Recovery and Business Continuity
Know the difference in purpose between a disaster recovery plan (restoring systems and data) and a business continuity plan (keeping the organization operating). Expect to separate natural from human-caused disasters and to recognize backup and recovery controls.
Key Takeaway
When a Domain 4 question describes a finding, ask two things in order: how severe is it given the asset's data classification, and what is the most proportionate mitigation? Answers that jump straight to the most extreme control are usually wrong.
Domain 5: Incident Handling
The final domain connects monitoring, investigation, compliance and response into one workflow.
Monitoring and Escalation
Recognize suspicious activity and know when to hand it up.
- The role of SIEM (aggregating and correlating events) and SOAR (automating response)
- Monitoring network data, packet captures and log file entries to identify suspicious events
Forensics and Attribution
Frameworks and evidence handling.
- Cyber Kill Chain, MITRE ATT&CK Matrix and the Diamond Model
- Tactics, Techniques and Procedures (TTP)
- Sources of evidence, artifacts, evidence preservation and chain of custody
Compliance and Response Lifecycle
Reporting duties and the formal process.
- How GDPR, HIPAA, PCI-DSS, FERPA and FISMA affect reporting and notification requirements
- Incident response policies, plans and procedures
- The incident response lifecycle stages drawn from NIST Special Publication 800-61 (sections 2.3 and 3.1 through 3.4)
Confusable Pairs Worth Memorizing
Cybersecurity entry-level exams love near-synonyms. This table pairs the terms the CCST Cybersecurity objectives put side by side, so you can drill the distinctions quickly.
| Pair | How They Differ |
|---|---|
| Phishing vs. spear phishing | Broad mass email versus a message crafted for a specific target |
| Vishing vs. smishing | Voice call versus text message |
| Authentication vs. authorization | Proving identity versus determining permitted actions |
| Hashing vs. encryption | One-way integrity check versus reversible confidentiality |
| IDS vs. IPS | Detects and alerts versus can block traffic inline |
| Vulnerability vs. risk | A weakness versus the likelihood and impact of its exploitation |
| Active vs. passive reconnaissance | Directly probing a target versus observing without touching it |
| DRP vs. BCP | Restoring systems and data versus sustaining business operations |
| SIEM vs. SOAR | Correlating and alerting on events versus orchestrating automated response |
| Data in transit vs. at rest vs. in use | Moving across a network, stored on media, or actively being processed |
Scheduling Your Review by Domain
Since official weights are unpublished, a balanced schedule makes sense. Place the conceptual domains first because later domains reuse their vocabulary, and finish with incident handling because it synthesizes everything else.
Domain 1: Principles
- Lock down definitions, CIA mapping and the social engineering variants
- Drill AAA, MFA, hashing, PKI and the three data states
Domain 2: Network Security
- Pair each protocol with its weakness
- Practice CIDR, NAT and segmentation, then secure SoHo wireless choices
Domain 3: Endpoints
- Run netstat, nslookup and tcpdump yourself rather than only reading about them
- Review patching, logs, compliance frameworks and malware remediation steps
Domains 4 and 5, then full review
- Cover risk ranking, DRP versus BCP, SIEM and SOAR, forensics frameworks and the NIST lifecycle
- Finish with timed practice at the 50-minute pace
Adjust the pacing to your background. A candidate with networking experience can compress Week 2, while someone newer to IT may want to double the endpoint week. Timed practice matters because the exam is only 50 minutes; you can sharpen that pacing with the question sets on the CCST-C practice test site.
Where This Credential Fits in Your Career
CCST Cybersecurity is positioned as an entry-level credential. The domains map naturally to the day-to-day work of help desk, IT support and junior security roles: reading logs, applying patches, checking endpoint compliance, escalating suspicious events and following an incident response plan. Employers looking for support technicians with security awareness are the natural audience. For a closer look at the job landscape, see CCST-C Jobs, and for money-related questions, review the CCST-C Salary Guide 2026: Complete Earnings Analysis and Is the CCST-C Certification Worth It? Complete ROI Analysis 2026.
Before registering, confirm the live fee and scheduling process, and compare it against your budget using the CCST-C Certification Cost 2026: Complete Pricing Breakdown. When you are ready to test yourself against realistic questions, the main practice test hub is the fastest way to find your weak domains.
Frequently Asked Questions
Cisco lists exam 100-160 at 50 minutes with a fee of USD 125. Always confirm the current figures on Cisco's official exam page and the Pearson VUE listing, since pricing and policies can change.
They are Essential Security Principles, Basic Network Security Concepts, Endpoint Security Concepts, Vulnerability Assessment and Risk Management, and Incident Handling. Cisco publishes the objectives for each but has not released official percentage weights.
The objectives describe a successful candidate as having about 150 hours of instruction and hands-on experience. That is a description of expected preparation, not a stated mandatory prerequisite. See the requirements article for full eligibility details.
A numeric passing score and question count were not established in the official source material this cheat sheet relies on, so check Cisco's exam page for current information rather than trusting unofficial figures. The CCST-C Passing Score 2026 article covers what is and is not known.
For commands, know netstat, nslookup and tcpdump. For frameworks and standards, know the Cyber Kill Chain, MITRE ATT&CK Matrix, the Diamond Model, and the NIST SP 800-61 incident response lifecycle. Also recognize compliance regimes such as GDPR, HIPAA, PCI DSS, FERPA and FISMA.