- Why the Domain Structure Matters for CCST-C
- Exam 100-160 Snapshot
- Domain 1: Essential Security Principles
- Domain 2: Basic Network Security Concepts
- Domain 3: Endpoint Security Concepts
- Domain 4: Vulnerability Assessment and Risk Management
- Domain 5: Incident Handling
- Where the Five Domains Overlap
- Sequencing the Domains in Your Prep
- Frequently Asked Questions
- Exam 100-160 covers five official domains, from Essential Security Principles through Incident Handling.
- Cisco lists the exam at 50 minutes and USD 125; no official domain weights are published.
- Domain 3 is hands-on flavored: netstat, nslookup, tcpdump, Event Viewer, syslog and patching all appear.
- Domain 5 builds on NIST SP 800-61, the Cyber Kill Chain, MITRE ATT&CK and the Diamond Model.
Why the Domain Structure Matters for CCST-C
The Cisco Certified Support Technician - Cybersecurity exam is organized around five objective domains published in Cisco's official exam objectives document. Everything you can be tested on traces back to that document, which makes the domain list the most reliable study map you have. If a topic does not appear under one of the five domains, it is unlikely to be the focus of a scored question; if it does appear, you should be able to explain it in plain language and recognize it in a scenario.
This guide walks through each domain using Cisco's own topic language, explains what candidates actually need to be able to do, and shows how the domains connect. If you are still deciding whether this credential fits your goals, start with What Is CCST-C Certification? and then come back here for the content breakdown.
Exam 100-160 Snapshot
Before diving into the domains, here is what is firmly established about the exam itself. Cisco lists exam 100-160 as a 50-minute exam with a fee of USD 125. Registration runs through the Certiport/Pearson VUE delivery path for Cisco CCST exams. For scheduling mechanics and testing windows, see CCST-C Exam Dates 2026, and for a fuller fee picture including retakes and study materials, see CCST-C Certification Cost 2026.
| Item | What the sources establish |
|---|---|
| Exam code | 100-160 |
| Duration | 50 minutes |
| Fee | USD 125 |
| Official domains | Five objective domains |
| Domain percentage weights | Not established in the supplied source context |
| Question count | Not established in the supplied source context |
| Numeric passing score | Not established in the supplied source context |
| Objective document | CCST Cybersecurity OD 0924 (copyright 2025) |
Notice what is absent: Cisco's objectives document does not publish domain percentages in the material we rely on here, so any site claiming exact weightings should be treated with caution. Our approach is to treat all five domains as testable and spend time in proportion to how many distinct skills each one lists. For the scoring question specifically, read CCST-C Passing Score 2026.
The objectives also describe a successful candidate as someone with roughly 150 hours of instruction and hands-on experience. That is a description of the expected preparation level, not a stated eligibility gate. Details on that distinction live in CCST-C Requirements 2026.
Domain 1: Essential Security Principles
Domain 1 is the vocabulary and mental-model domain. It is also the widest in terms of distinct subtopics, because it spans fundamentals, threats, access management and cryptography. Candidates who skim it often find that later domains feel harder than they should, since Domains 2 through 5 assume you already speak this language fluently.
Core security principles
You are expected to define vulnerabilities, threats, exploits, risks and attack vectors, and to keep those terms distinct. A vulnerability is a weakness; a threat is something that can exploit it; an exploit is the technique or tool that does so; risk is the resulting likelihood-and-impact picture. The domain also covers hardening, defense-in-depth, the CIA triad (confidentiality, integrity, availability), types of attackers, reasons for attacks and a code of ethics.
Threats and vulnerabilities you must recognize
The objectives name a specific catalog. Expect scenario wording that describes behavior and asks you to identify the category.
- Malware, ransomware, denial of service and botnets
- Social engineering: tailgating, phishing, spear phishing, vishing and smishing
- Physical attacks, man in the middle and IoT vulnerabilities
- Insider threats and Advanced Persistent Threats (APT)
A reliable way to prepare is to practice distinguishing near neighbors. Phishing versus spear phishing versus vishing versus smishing differ by targeting and channel. Tailgating is a physical-access technique, not a network one. An APT is defined by persistence and sophistication, not by any single malware family.
Access management and encryption
Access management centers on AAA (authentication, authorization and accounting), RADIUS, multifactor authentication and password policies. Know what each A does and be able to match a described control to the right one. Encryption coverage includes encryption types, hashing, certificates, public key infrastructure (PKI), strong versus weak algorithms, protection of data in transit, at rest and in use, and which protocols rely on encryption.
Domain 2: Basic Network Security Concepts
Domain 2 is where networking knowledge meets security thinking. If you have taken CCST Networking or a similar course, much of the infrastructure will feel familiar, but the exam asks you to view it through an attacker-and-defender lens.
TCP/IP protocol weaknesses
The objectives list TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS. For each, know what it does and how it can be abused.
- ARP: trust-based resolution that enables spoofing and man-in-the-middle positioning
- DHCP: rogue servers and address exhaustion
- DNS: spoofing, poisoning and tunneling concerns
- ICMP: reconnaissance and flooding uses
- HTTP: plaintext exposure compared with encrypted alternatives
Addressing and segmentation
Expect questions on how addressing affects security: IPv4 and IPv6, MAC addresses, network segmentation, CIDR notation, NAT and public versus private networks. You should be able to read a CIDR prefix, explain why segmentation limits lateral movement, and describe what NAT does and does not protect.
Infrastructure, wireless and secure access
The infrastructure topics include network security architecture, DMZ, virtualization, cloud, honeypots, proxy servers, IDS and IPS. Know the difference between detecting (IDS) and preventing (IPS), why a DMZ exists, and what a honeypot is for.
The objectives also call for setting up a secure wireless SoHo network, covering MAC address filtering, encryption standards and protocols, and SSID considerations. Be ready to rank wireless protections by strength and to explain why MAC filtering and hiding an SSID are weak controls on their own. Finally, secure access technologies include ACLs, firewalls, VPNs and NAC.
Key Takeaway
For Domain 2, pair every technology with the threat it addresses. An ACL filters traffic, a VPN protects data in transit across untrusted networks, and NAC governs which devices may join. If you can state the problem each one solves, scenario questions become much easier.
Domain 3: Endpoint Security Concepts
Domain 3 is the most practical domain, and the one that rewards actual hands-on time. It covers operating systems, diagnostic tools, policy verification, updates, logs and malware removal. Candidates who have only read about these topics tend to struggle with the tool-output interpretation.
Operating system security and tools
You should understand security features across Windows, macOS and Linux, including Windows Defender, host-based firewalls, the command line, PowerShell, file and directory permissions and privilege escalation. The objectives also name three assessment tools: netstat (connections and listening ports), nslookup (DNS queries) and tcpdump (packet capture). Practice running each and reading the output rather than only memorizing definitions.
Verifying endpoints meet policy
This objective is broad and administrative in tone. It connects technical controls to organizational and regulatory requirements.
- Hardware and software inventory, and asset management
- Program deployment, app distribution and configuration management
- Data backups and data encryption
- BYOD device management
- Compliance references: PCI DSS, HIPAA and GDPR
Updates, logs and malware removal
Patching covers Windows Update, application updates, device drivers and firmware. Know why firmware and drivers are easy to overlook and why unpatched software is a leading attack path. Log interpretation covers Event Viewer, audit logs, system and application logs, syslog and anomaly identification. The skill being tested is noticing what is unusual, such as repeated failed logons or an unexpected service start.
Malware removal rounds out the domain: scanning systems, reviewing scan logs and carrying out remediation. Understand the order of operations at a conceptual level and what a scan log is telling you.
Domain 4: Vulnerability Assessment and Risk Management
Domain 4 shifts from individual controls to organizational thinking: how weaknesses are found, how intelligence is used, how risk is ranked and how organizations plan for disruption.
Vulnerability management and threat intelligence
Vulnerability management includes identification, management and mitigation, and the difference between active and passive reconnaissance, with port scanning and automation as named examples. Threat intelligence topics include the uses and limitations of vulnerability databases, Common Vulnerabilities and Exposures (CVEs), industry-standard tools, cybersecurity reports and news, subscription services, collective intelligence, and ad hoc versus automated intelligence. The objectives also stress documentation: updating it, and sharing it securely, before, during and after incidents.
The key judgment skill is recognizing limitations. A CVE entry identifies a known vulnerability but does not tell you whether it matters in your environment. That distinction between a vulnerability and a risk is a recurring theme.
Risk management and continuity
Risk management essentials
Be able to move from a finding to a decision.
- Vulnerability versus risk, and ranking risks
- Approaches to risk management and mitigation strategies
- Risk levels and data classification risks
- Security assessments of IT systems
Disaster recovery and business continuity planning close the domain. You should distinguish natural from human-caused disasters, describe the features of a DRP versus a BCP, and explain backup and disaster recovery controls. A common point of confusion is that continuity planning keeps the business operating, while disaster recovery focuses on restoring systems and data.
Domain 5: Incident Handling
Domain 5 asks you to think like a junior analyst on a security team. It covers monitoring and escalation, forensics and attribution, compliance-driven reporting and the formal response lifecycle.
Monitoring and escalation
You need to understand the role of SIEM and SOAR, how network data is monitored for incidents, and how to work with packet captures and log entries to identify suspicious events. Just as important is knowing when escalation is required. At this certification level, recognizing that something exceeds your authority is a tested competence, not a failure.
Forensics and attribution frameworks
Frameworks and evidence handling
The objectives name specific models. Learn what each one is for, not just its name.
- Cyber Kill Chain: staged view of an intrusion
- MITRE ATT&CK Matrix: catalog of adversary tactics and techniques
- Diamond Model: relationships among adversary, capability, infrastructure and victim
- Tactics, Techniques and Procedures (TTP) as behavioral fingerprints
- Sources of evidence, artifacts, evidence preservation and chain of custody
Compliance and the response lifecycle
The objectives cover how GDPR, HIPAA, PCI-DSS, FERPA and FISMA affect incident handling, particularly reporting and notification requirements. You are not expected to be a lawyer, but you should know that regulated data changes who must be told and when.
The response lifecycle is anchored to NIST Special Publication 800-61 (sections 2.3 and 3.1 through 3.4), covering policies, plans, procedures and the lifecycle stages. Learn the stages in order and what happens in each, since sequencing questions are a natural fit for this material.
Key Takeaway
Chain of custody and evidence preservation are easy marks if you prepare and easy losses if you assume common sense will carry you. Know why evidence handling must be documented and why altering a system can destroy it.
Where the Five Domains Overlap
The domains are separate headings, but real questions blend them. A scenario about a phishing email touches Domain 1 (social engineering), Domain 3 (checking logs on the affected endpoint) and Domain 5 (escalation and evidence preservation). A question about an exposed server can combine Domain 2 (segmentation and firewalls), Domain 4 (CVE and risk ranking) and Domain 5 (response steps).
| Scenario theme | Domains involved | What to recall |
|---|---|---|
| Suspicious email reported | 1, 3, 5 | Phishing variants, log review, escalation |
| Unpatched system found | 3, 4 | Patching types, CVE use, risk ranking |
| Rogue device on network | 2, 3, 5 | NAC, ARP/DHCP abuse, evidence handling |
| Data breach with regulated data | 1, 4, 5 | Classification, compliance, notification |
Understanding this overlap also helps with expectations about difficulty. The exam rewards breadth and connected reasoning more than deep specialization. For a candid look at how that plays out, read How Hard Is the CCST-C Exam?, and for what published data does and does not tell us, see CCST-C Pass Rate 2026.
Sequencing the Domains in Your Prep
Because no official weights are published, a sensible plan orders domains by dependency rather than by guessed percentage. Domain 1 comes first because its vocabulary underpins everything else. Domain 2 and Domain 3 follow as the technical core. Domain 4 and Domain 5 come last because they assume you can already recognize threats, controls and endpoint evidence.
Domain 1: Essential Security Principles
- Lock down threat names and the CIA triad
- Drill AAA, RADIUS, MFA, hashing versus encryption and PKI
Domain 2: Basic Network Security Concepts
- Map each TCP/IP protocol to its abuse case
- Practice CIDR reading, then ACL, firewall, VPN, NAC and wireless setup
Domain 3: Endpoint Security Concepts
- Run netstat, nslookup and tcpdump; read Event Viewer and syslog
- Review patching types and compliance references
Domains 4 and 5, then full review
- Risk ranking, DRP versus BCP, SIEM/SOAR, kill chain, ATT&CK, NIST 800-61 stages
- Finish with mixed practice questions across all five domains
Adjust the pace to your background. A candidate with networking experience can compress Week 2; someone new to command-line work should extend Week 3. For a fuller preparation plan, see the CCST-C Study Guide 2026, and use the CCST-C Cheat Sheet for a final-day review. When you are ready to test retention across all five areas, take a few timed sets on the CCST-C practice test site and note which domain keeps costing you points.
How the Domains Connect to Entry-Level Roles
The five domains line up with the daily work of entry-level security and IT support roles: triaging alerts and checking logs (Domains 3 and 5), maintaining patched and inventoried endpoints (Domain 3), supporting firewall and access changes (Domain 2) and following risk and compliance procedures (Domain 4). That alignment is the point of the certification: it signals foundational, job-relevant literacy rather than deep specialization. To see how this translates into hiring, explore CCST-C Jobs, and for compensation discussion without inflated numbers, see the CCST-C Salary Guide and Is the CCST-C Certification Worth It?. You can also practice at ccstcexam.com to benchmark your readiness against each domain.
Frequently Asked Questions
The Cisco Certified Support Technician - Cybersecurity exam (100-160) has five official objective domains: Essential Security Principles, Basic Network Security Concepts, Endpoint Security Concepts, Vulnerability Assessment and Risk Management, and Incident Handling.
The source material used for this guide does not establish official domain percentages, so we do not state any. Treat all five domains as testable and prioritize by your own weak areas.
Cisco lists exam 100-160 as 50 minutes with a USD 125 fee. Question count and a numeric passing score are not established in the supplied sources, so check Cisco's official exam page before test day.
Start with Domain 1, Essential Security Principles. Its vocabulary on threats, CIA, AAA and encryption supports the network, endpoint, risk and incident handling domains that follow.
No. CCST Cybersecurity is a distinct certification. It overlaps with networking and security operations topics, but it has its own objectives document and its own five domains.