CCST-C logo
Focused certification exam prep
Start practice

CCST-C Exam Domains 2026: Complete Guide to All 5 Content Areas

TL;DR
  • Exam 100-160 covers five official domains, from Essential Security Principles through Incident Handling.
  • Cisco lists the exam at 50 minutes and USD 125; no official domain weights are published.
  • Domain 3 is hands-on flavored: netstat, nslookup, tcpdump, Event Viewer, syslog and patching all appear.
  • Domain 5 builds on NIST SP 800-61, the Cyber Kill Chain, MITRE ATT&CK and the Diamond Model.

Why the Domain Structure Matters for CCST-C

The Cisco Certified Support Technician - Cybersecurity exam is organized around five objective domains published in Cisco's official exam objectives document. Everything you can be tested on traces back to that document, which makes the domain list the most reliable study map you have. If a topic does not appear under one of the five domains, it is unlikely to be the focus of a scored question; if it does appear, you should be able to explain it in plain language and recognize it in a scenario.

This guide walks through each domain using Cisco's own topic language, explains what candidates actually need to be able to do, and shows how the domains connect. If you are still deciding whether this credential fits your goals, start with What Is CCST-C Certification? and then come back here for the content breakdown.

Identity check: CCST-C here means Cisco Certified Support Technician - Cybersecurity, exam 100-160. It is not the same as CCST Networking, and it is not the Cisco CyberOps Associate. The overlap in subject matter is real, but the exam objectives, level and intent differ.

Exam 100-160 Snapshot

Before diving into the domains, here is what is firmly established about the exam itself. Cisco lists exam 100-160 as a 50-minute exam with a fee of USD 125. Registration runs through the Certiport/Pearson VUE delivery path for Cisco CCST exams. For scheduling mechanics and testing windows, see CCST-C Exam Dates 2026, and for a fuller fee picture including retakes and study materials, see CCST-C Certification Cost 2026.

ItemWhat the sources establish
Exam code100-160
Duration50 minutes
FeeUSD 125
Official domainsFive objective domains
Domain percentage weightsNot established in the supplied source context
Question countNot established in the supplied source context
Numeric passing scoreNot established in the supplied source context
Objective documentCCST Cybersecurity OD 0924 (copyright 2025)

Notice what is absent: Cisco's objectives document does not publish domain percentages in the material we rely on here, so any site claiming exact weightings should be treated with caution. Our approach is to treat all five domains as testable and spend time in proportion to how many distinct skills each one lists. For the scoring question specifically, read CCST-C Passing Score 2026.

The objectives also describe a successful candidate as someone with roughly 150 hours of instruction and hands-on experience. That is a description of the expected preparation level, not a stated eligibility gate. Details on that distinction live in CCST-C Requirements 2026.

Domain 1: Essential Security Principles

Domain 1 is the vocabulary and mental-model domain. It is also the widest in terms of distinct subtopics, because it spans fundamentals, threats, access management and cryptography. Candidates who skim it often find that later domains feel harder than they should, since Domains 2 through 5 assume you already speak this language fluently.

Core security principles

You are expected to define vulnerabilities, threats, exploits, risks and attack vectors, and to keep those terms distinct. A vulnerability is a weakness; a threat is something that can exploit it; an exploit is the technique or tool that does so; risk is the resulting likelihood-and-impact picture. The domain also covers hardening, defense-in-depth, the CIA triad (confidentiality, integrity, availability), types of attackers, reasons for attacks and a code of ethics.

Threats and vulnerabilities you must recognize

The objectives name a specific catalog. Expect scenario wording that describes behavior and asks you to identify the category.

  • Malware, ransomware, denial of service and botnets
  • Social engineering: tailgating, phishing, spear phishing, vishing and smishing
  • Physical attacks, man in the middle and IoT vulnerabilities
  • Insider threats and Advanced Persistent Threats (APT)

A reliable way to prepare is to practice distinguishing near neighbors. Phishing versus spear phishing versus vishing versus smishing differ by targeting and channel. Tailgating is a physical-access technique, not a network one. An APT is defined by persistence and sophistication, not by any single malware family.

Access management and encryption

Access management centers on AAA (authentication, authorization and accounting), RADIUS, multifactor authentication and password policies. Know what each A does and be able to match a described control to the right one. Encryption coverage includes encryption types, hashing, certificates, public key infrastructure (PKI), strong versus weak algorithms, protection of data in transit, at rest and in use, and which protocols rely on encryption.

Common trap: Hashing is not encryption. Hashing supports integrity checking and is one-way; encryption is designed to be reversible by an authorized key holder. Questions often test whether you can tell which property a control actually provides.

Domain 2: Basic Network Security Concepts

Domain 2 is where networking knowledge meets security thinking. If you have taken CCST Networking or a similar course, much of the infrastructure will feel familiar, but the exam asks you to view it through an attacker-and-defender lens.

TCP/IP protocol weaknesses

The objectives list TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS. For each, know what it does and how it can be abused.

  • ARP: trust-based resolution that enables spoofing and man-in-the-middle positioning
  • DHCP: rogue servers and address exhaustion
  • DNS: spoofing, poisoning and tunneling concerns
  • ICMP: reconnaissance and flooding uses
  • HTTP: plaintext exposure compared with encrypted alternatives

Addressing and segmentation

Expect questions on how addressing affects security: IPv4 and IPv6, MAC addresses, network segmentation, CIDR notation, NAT and public versus private networks. You should be able to read a CIDR prefix, explain why segmentation limits lateral movement, and describe what NAT does and does not protect.

Infrastructure, wireless and secure access

The infrastructure topics include network security architecture, DMZ, virtualization, cloud, honeypots, proxy servers, IDS and IPS. Know the difference between detecting (IDS) and preventing (IPS), why a DMZ exists, and what a honeypot is for.

The objectives also call for setting up a secure wireless SoHo network, covering MAC address filtering, encryption standards and protocols, and SSID considerations. Be ready to rank wireless protections by strength and to explain why MAC filtering and hiding an SSID are weak controls on their own. Finally, secure access technologies include ACLs, firewalls, VPNs and NAC.

Key Takeaway

For Domain 2, pair every technology with the threat it addresses. An ACL filters traffic, a VPN protects data in transit across untrusted networks, and NAC governs which devices may join. If you can state the problem each one solves, scenario questions become much easier.

Domain 3: Endpoint Security Concepts

Domain 3 is the most practical domain, and the one that rewards actual hands-on time. It covers operating systems, diagnostic tools, policy verification, updates, logs and malware removal. Candidates who have only read about these topics tend to struggle with the tool-output interpretation.

Operating system security and tools

You should understand security features across Windows, macOS and Linux, including Windows Defender, host-based firewalls, the command line, PowerShell, file and directory permissions and privilege escalation. The objectives also name three assessment tools: netstat (connections and listening ports), nslookup (DNS queries) and tcpdump (packet capture). Practice running each and reading the output rather than only memorizing definitions.

Verifying endpoints meet policy

This objective is broad and administrative in tone. It connects technical controls to organizational and regulatory requirements.

  • Hardware and software inventory, and asset management
  • Program deployment, app distribution and configuration management
  • Data backups and data encryption
  • BYOD device management
  • Compliance references: PCI DSS, HIPAA and GDPR

Updates, logs and malware removal

Patching covers Windows Update, application updates, device drivers and firmware. Know why firmware and drivers are easy to overlook and why unpatched software is a leading attack path. Log interpretation covers Event Viewer, audit logs, system and application logs, syslog and anomaly identification. The skill being tested is noticing what is unusual, such as repeated failed logons or an unexpected service start.

Malware removal rounds out the domain: scanning systems, reviewing scan logs and carrying out remediation. Understand the order of operations at a conceptual level and what a scan log is telling you.

Hands-on advantage: Domain 3 is where lab time pays off most. Run netstat on your own machine, open Event Viewer and filter for failed logons, and read a syslog sample. Ten minutes of real output beats an hour of rereading definitions. If you want structured lab ideas, see CCST-C Training.

Domain 4: Vulnerability Assessment and Risk Management

Domain 4 shifts from individual controls to organizational thinking: how weaknesses are found, how intelligence is used, how risk is ranked and how organizations plan for disruption.

Vulnerability management and threat intelligence

Vulnerability management includes identification, management and mitigation, and the difference between active and passive reconnaissance, with port scanning and automation as named examples. Threat intelligence topics include the uses and limitations of vulnerability databases, Common Vulnerabilities and Exposures (CVEs), industry-standard tools, cybersecurity reports and news, subscription services, collective intelligence, and ad hoc versus automated intelligence. The objectives also stress documentation: updating it, and sharing it securely, before, during and after incidents.

The key judgment skill is recognizing limitations. A CVE entry identifies a known vulnerability but does not tell you whether it matters in your environment. That distinction between a vulnerability and a risk is a recurring theme.

Risk management and continuity

Risk management essentials

Be able to move from a finding to a decision.

  • Vulnerability versus risk, and ranking risks
  • Approaches to risk management and mitigation strategies
  • Risk levels and data classification risks
  • Security assessments of IT systems

Disaster recovery and business continuity planning close the domain. You should distinguish natural from human-caused disasters, describe the features of a DRP versus a BCP, and explain backup and disaster recovery controls. A common point of confusion is that continuity planning keeps the business operating, while disaster recovery focuses on restoring systems and data.

Domain 5: Incident Handling

Domain 5 asks you to think like a junior analyst on a security team. It covers monitoring and escalation, forensics and attribution, compliance-driven reporting and the formal response lifecycle.

Monitoring and escalation

You need to understand the role of SIEM and SOAR, how network data is monitored for incidents, and how to work with packet captures and log entries to identify suspicious events. Just as important is knowing when escalation is required. At this certification level, recognizing that something exceeds your authority is a tested competence, not a failure.

Forensics and attribution frameworks

Frameworks and evidence handling

The objectives name specific models. Learn what each one is for, not just its name.

  • Cyber Kill Chain: staged view of an intrusion
  • MITRE ATT&CK Matrix: catalog of adversary tactics and techniques
  • Diamond Model: relationships among adversary, capability, infrastructure and victim
  • Tactics, Techniques and Procedures (TTP) as behavioral fingerprints
  • Sources of evidence, artifacts, evidence preservation and chain of custody

Compliance and the response lifecycle

The objectives cover how GDPR, HIPAA, PCI-DSS, FERPA and FISMA affect incident handling, particularly reporting and notification requirements. You are not expected to be a lawyer, but you should know that regulated data changes who must be told and when.

The response lifecycle is anchored to NIST Special Publication 800-61 (sections 2.3 and 3.1 through 3.4), covering policies, plans, procedures and the lifecycle stages. Learn the stages in order and what happens in each, since sequencing questions are a natural fit for this material.

Key Takeaway

Chain of custody and evidence preservation are easy marks if you prepare and easy losses if you assume common sense will carry you. Know why evidence handling must be documented and why altering a system can destroy it.

Where the Five Domains Overlap

The domains are separate headings, but real questions blend them. A scenario about a phishing email touches Domain 1 (social engineering), Domain 3 (checking logs on the affected endpoint) and Domain 5 (escalation and evidence preservation). A question about an exposed server can combine Domain 2 (segmentation and firewalls), Domain 4 (CVE and risk ranking) and Domain 5 (response steps).

Scenario themeDomains involvedWhat to recall
Suspicious email reported1, 3, 5Phishing variants, log review, escalation
Unpatched system found3, 4Patching types, CVE use, risk ranking
Rogue device on network2, 3, 5NAC, ARP/DHCP abuse, evidence handling
Data breach with regulated data1, 4, 5Classification, compliance, notification

Understanding this overlap also helps with expectations about difficulty. The exam rewards breadth and connected reasoning more than deep specialization. For a candid look at how that plays out, read How Hard Is the CCST-C Exam?, and for what published data does and does not tell us, see CCST-C Pass Rate 2026.

Sequencing the Domains in Your Prep

Because no official weights are published, a sensible plan orders domains by dependency rather than by guessed percentage. Domain 1 comes first because its vocabulary underpins everything else. Domain 2 and Domain 3 follow as the technical core. Domain 4 and Domain 5 come last because they assume you can already recognize threats, controls and endpoint evidence.

Week 1

Domain 1: Essential Security Principles

  • Lock down threat names and the CIA triad
  • Drill AAA, RADIUS, MFA, hashing versus encryption and PKI
Week 2

Domain 2: Basic Network Security Concepts

  • Map each TCP/IP protocol to its abuse case
  • Practice CIDR reading, then ACL, firewall, VPN, NAC and wireless setup
Week 3

Domain 3: Endpoint Security Concepts

  • Run netstat, nslookup and tcpdump; read Event Viewer and syslog
  • Review patching types and compliance references
Week 4

Domains 4 and 5, then full review

  • Risk ranking, DRP versus BCP, SIEM/SOAR, kill chain, ATT&CK, NIST 800-61 stages
  • Finish with mixed practice questions across all five domains

Adjust the pace to your background. A candidate with networking experience can compress Week 2; someone new to command-line work should extend Week 3. For a fuller preparation plan, see the CCST-C Study Guide 2026, and use the CCST-C Cheat Sheet for a final-day review. When you are ready to test retention across all five areas, take a few timed sets on the CCST-C practice test site and note which domain keeps costing you points.

How the Domains Connect to Entry-Level Roles

The five domains line up with the daily work of entry-level security and IT support roles: triaging alerts and checking logs (Domains 3 and 5), maintaining patched and inventoried endpoints (Domain 3), supporting firewall and access changes (Domain 2) and following risk and compliance procedures (Domain 4). That alignment is the point of the certification: it signals foundational, job-relevant literacy rather than deep specialization. To see how this translates into hiring, explore CCST-C Jobs, and for compensation discussion without inflated numbers, see the CCST-C Salary Guide and Is the CCST-C Certification Worth It?. You can also practice at ccstcexam.com to benchmark your readiness against each domain.

Frequently Asked Questions

How many domains are on the CCST-C exam?

The Cisco Certified Support Technician - Cybersecurity exam (100-160) has five official objective domains: Essential Security Principles, Basic Network Security Concepts, Endpoint Security Concepts, Vulnerability Assessment and Risk Management, and Incident Handling.

Does Cisco publish percentage weights for each domain?

The source material used for this guide does not establish official domain percentages, so we do not state any. Treat all five domains as testable and prioritize by your own weak areas.

How long is the exam and what does it cost?

Cisco lists exam 100-160 as 50 minutes with a USD 125 fee. Question count and a numeric passing score are not established in the supplied sources, so check Cisco's official exam page before test day.

Which domain should I study first?

Start with Domain 1, Essential Security Principles. Its vocabulary on threats, CIA, AAA and encryption supports the network, endpoint, risk and incident handling domains that follow.

Is CCST-C the same as CCST Networking or CyberOps Associate?

No. CCST Cybersecurity is a distinct certification. It overlaps with networking and security operations topics, but it has its own objectives document and its own five domains.

Ready to pass your CCST-C exam?

Put this into practice with free CCST-C questions across every exam domain.