CCST-C logo
Focused certification exam prep
Start practice

CCST-C Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • Exam 100-160 is listed by Cisco at 50 minutes and a USD125 fee.
  • The official objectives define five domains; no domain percentage weights are published, so study all five evenly.
  • Domain 3 and Domain 5 reward hands-on familiarity with netstat, nslookup, tcpdump, Event Viewer and the NIST 800-61 lifecycle.
  • CCST Cybersecurity is a different credential from CCST Networking and from Cisco CyberOps Associate.

What You Are Actually Studying For

The Cisco Certified Support Technician - Cybersecurity exam (100-160) is Cisco's entry-level cybersecurity credential, built around the work of a junior technician who supports security operations, helps harden endpoints and networks, and recognizes when an event needs to be escalated. If you are still orienting yourself, What Is CCST-C Certification? covers the basics, and the CCST-C certification overview explains how the credential fits into Cisco's lineup.

One distinction matters before you open a single study resource: this exam is not CCST Networking, and it is not Cisco CyberOps Associate. Networking content appears here only through a security lens (how DHCP, ARP and DNS can be abused, how segmentation limits damage). The incident handling domain is introductory, not the analyst-level depth you would expect from CyberOps. Study to the scope Cisco actually published and you will avoid wasting weeks on material that will never appear.

Your single source of truth: Cisco publishes the Cisco Certified Support Technician Cybersecurity Exam Objectives document (file name "CCST Cybersecurity OD 0924.pdf"). Every claim in this guide traces back to it. Print it, and treat each bullet as a checkbox you must be able to explain out loud without notes.

Exam 100-160 Logistics: Time, Fee and What Is Not Published

Cisco lists exam 100-160 at 50 minutes with a USD125 fee. Registration runs through Cisco's Certiport/Pearson VUE channel for the CCST Cybersecurity exam. For the full cost picture, including retakes and vouchers, see the CCST-C certification cost breakdown, and for scheduling windows check CCST-C exam dates and testing windows.

Just as important is what is not established in the official material this guide relies on: there are no published domain percentage weights, no confirmed question count, and no confirmed numeric passing score. Be wary of any site that quotes precise weights or a magic cut score as fact. The practical consequence is simple: you cannot safely skip a domain on the theory that it is "low weight." Plan to be competent across all five. Our page on the CCST-C passing score tracks what is and is not confirmed.

ItemWhat Is Established
Exam code100-160 (Cisco Certified Support Technician - Cybersecurity)
Listed duration50 minutes
Listed feeUSD125
Objective domainsFive, defined in the official Exam Objectives document
Domain weightsNot published in the sources used here
Question count / passing scoreNot established here; confirm with Cisco before test day
Suggested preparationCisco describes about 150 hours of instruction and hands-on experience for a successful candidate; this is a description, not a mandatory prerequisite

That 150-hour figure deserves a careful reading. It describes the preparation of a typical successful candidate, so use it as a planning benchmark rather than an entry gate. Eligibility questions are answered in CCST-C requirements and eligibility.

With only 50 minutes on the clock, pacing is part of the preparation. You will not have time to deliberate at length over any single item, which favors candidates who know the vocabulary cold. Definitions and distinctions (threat versus vulnerability versus risk, IDS versus IPS, authentication versus authorization) should be automatic, leaving your limited time for scenario-style questions.

Domain 1: Essential Security Principles

This is the vocabulary and conceptual foundation for everything else. Because later domains assume you already speak the language, master it first. For a full breakdown of all five areas, see the complete CCST-C exam domains guide.

Core Principles and Terminology

You must define, and distinguish between, the building blocks of security thinking.

  • Vulnerabilities, threats, exploits, risks and attack vectors, and how each relates to the others
  • Hardening and defense-in-depth as layered controls
  • The CIA triad: confidentiality, integrity, availability
  • Types of attackers, reasons for attacks and the code of ethics

Common Threats and Vulnerabilities

Expect to recognize each threat from a short description of its behavior.

  • Malware, ransomware, denial of service and botnets
  • Social engineering: tailgating, phishing, spear phishing, vishing and smishing
  • Physical attacks, man-in-the-middle, IoT vulnerabilities, insider threats and Advanced Persistent Threats (APT)

Access Management and Encryption

Two topic clusters that candidates often treat superficially and then regret.

  • AAA (authentication, authorization, accounting), RADIUS, multifactor authentication and password policies
  • Encryption types, hashing, certificates and PKI
  • Strong versus weak algorithms, and protecting data in transit, at rest and in use
  • Which protocols use encryption

A reliable way to retain this domain is to attach each threat to the control that counters it: tailgating maps to physical access controls, phishing to user awareness and MFA, ransomware to backups and segmentation. Questions rarely ask for a definition in isolation; they describe a scenario and expect you to name the threat or the best control.

Domain 2: Basic Network Security Concepts

You do not need to be a network engineer, but you do need to understand how everyday protocols can be abused and which devices and configurations reduce exposure.

Protocol Weaknesses and Addressing

Know what each protocol does and the classic attack it enables.

  • TCP, UDP, HTTP, ARP, ICMP, DHCP and DNS vulnerabilities
  • IPv4 and IPv6 addressing, MAC addresses, CIDR notation and NAT
  • Public versus private networks and how segmentation limits the blast radius of an attack

Infrastructure and Secure Access

This is where architecture vocabulary shows up.

  • Network security architecture, DMZ, virtualization, cloud, honeypots and proxy servers
  • IDS versus IPS: detection versus active prevention
  • ACLs, firewalls, VPNs and NAC as access technologies
  • Securing a SoHo wireless network: MAC address filtering, encryption standards and protocols, and SSID considerations
Think in pairs: Many questions in this domain hinge on telling two similar things apart: IDS and IPS, firewall and proxy, DMZ and internal segment, VPN and NAC. Build a two-column list for each pair stating what it does, where it sits and what it cannot do. That single exercise covers a surprising share of the domain.

Domain 3: Endpoint Security Concepts

This domain is the most hands-on and the easiest to underestimate if you have mostly studied from slides. Candidates who have actually run the commands tend to find it easier.

Operating System Security and Endpoint Tools

Cover Windows, macOS and Linux at a conceptual level, with practical familiarity.

  • Windows Defender, host-based firewalls, the command line and PowerShell
  • File and directory permissions and privilege escalation
  • netstat, nslookup and tcpdump: what each reveals about an endpoint

Policy, Compliance and Maintenance

Verifying that systems meet organizational standards is a recurring theme.

  • Hardware and software inventory, asset management, program deployment and configuration management
  • Data backups and data encryption
  • PCI DSS, HIPAA and GDPR as drivers of endpoint requirements
  • BYOD device management and app distribution
  • Windows Update, application updates, drivers, firmware and patching

Logs and Malware Removal

Reading evidence and cleaning up afterward.

  • Event Viewer, audit logs, system and application logs, and syslog
  • Spotting anomalies in log entries
  • Scanning systems, reviewing scan logs and remediating malware

Domain 4: Vulnerability Assessment and Risk Management

This domain shifts from technical detail to process and judgment: how organizations find weaknesses, decide what matters most and plan for the worst.

Finding and Researching Weaknesses

Understand both the techniques and the sources of information.

  • Vulnerability identification, management and mitigation
  • Active versus passive reconnaissance, including port scanning and automation
  • Vulnerability databases, CVEs, cybersecurity reports, news and subscription services
  • Ad hoc versus automated threat intelligence, and the limits of each source
  • Secure sharing and updating of documentation before, during and after incidents

Risk, Recovery and Continuity

The distinction between a vulnerability and a risk is tested directly.

  • Vulnerability versus risk, ranking risks, risk levels and mitigation strategies
  • Approaches to risk management and data classification risks
  • Security assessments of IT systems
  • Natural and human-caused disasters, DRP and BCP features, and backup and recovery controls

Remember the logic: a vulnerability is a weakness, while risk combines the likelihood of exploitation with the impact if it happens. Questions often present several findings and ask which should be addressed first, which requires thinking about both factors rather than just severity labels.

Domain 5: Incident Handling

The final domain ties everything together, from noticing something odd to preserving evidence and following a defined response process.

Monitoring, Forensics and Frameworks

Know the roles of tools and the vocabulary of attack analysis.

  • The role of SIEM and SOAR, packet captures and log entries, and when to escalate a suspicious event
  • Cyber Kill Chain, MITRE ATT&CK Matrix and the Diamond Model
  • Tactics, Techniques and Procedures (TTP), sources of evidence, artifacts, evidence preservation and chain of custody

Compliance and the Response Lifecycle

Reporting duties and process structure.

  • How GDPR, HIPAA, PCI-DSS, FERPA and FISMA affect reporting and notification
  • Incident response policies, plans and procedures
  • The lifecycle stages drawn from NIST Special Publication 800-61 (sections 2.3 and 3.1 to 3.4)

Key Takeaway

Read the relevant NIST SP 800-61 sections named in the objectives rather than relying on a summary alone. Knowing the order of the lifecycle stages and what happens in each is a dependable source of points, and it is one of the few places where the exam points you to a specific external document.

Sequencing the Domains Across Five Weeks

The order below follows dependency, not difficulty: vocabulary first, then the systems those concepts apply to, then process. Adjust the pace to your own background and the roughly 150 hours Cisco describes for a typical successful candidate. Our CCST-C difficulty guide can help you judge how much time you personally need.

Week 1

Domain 1 foundations

  • Memorize the threat, vulnerability, exploit and risk definitions and the CIA triad
  • Match each social engineering and malware type to its countermeasure
  • Work through AAA, RADIUS, MFA, hashing and PKI until you can explain each simply
Week 2

Domain 2 network security

  • Review how ARP, DHCP, DNS and ICMP are abused
  • Practice CIDR and private versus public address recognition
  • Build comparison pairs for IDS/IPS, firewall/proxy and VPN/NAC
Week 3

Domain 3 endpoints, hands-on

  • Run netstat, nslookup and tcpdump and interpret the output
  • Open Event Viewer and identify the log categories
  • Walk through patching, backup and compliance scenarios for PCI DSS, HIPAA and GDPR
Week 4

Domains 4 and 5 process

  • Practice distinguishing vulnerability from risk and ranking findings
  • Compare DRP and BCP, and review CVE and threat intelligence sources
  • Memorize the NIST 800-61 lifecycle and the Kill Chain, ATT&CK and Diamond Model purposes
Week 5

Integration and rehearsal

  • Take timed practice sets against the 50-minute limit
  • Revisit every weak objective bullet from the official document
  • Skim the CCST-C cheat sheet the day before

Hands-On Practice That Maps to the Objectives

You do not need an expensive lab. A home computer, a virtual machine and a spare router are enough to cover most of what the objectives name directly.

  • Inspect connections: run netstat on a Windows or Linux machine and identify listening ports and established sessions. Ask what each would mean during an investigation.
  • Query DNS: use nslookup to resolve names and notice how records change between hosts.
  • Capture traffic: run tcpdump on a Linux VM and watch ARP, DNS and TCP handshakes. Seeing the packets makes protocol vulnerabilities concrete.
  • Read logs: browse Event Viewer or a Linux syslog and practice spotting failed logons or unusual service changes.
  • Harden a wireless network: configure a SoHo router with a strong encryption standard, a non-default SSID and an understanding of why MAC filtering alone is weak.
  • Set permissions: create files and directories with restricted permissions and test what a standard account can and cannot do, which clarifies privilege escalation.

Structured courses can supplement this practice; see our overview of CCST-C training options for ways to combine instruction with labs.

Where Candidates Lose Points: Look-Alike Concepts

Entry-level exams reward precise distinctions. These pairs and clusters are worth drilling until the difference is instinctive.

Often ConfusedHow to Tell Them Apart
Vulnerability vs. riskA vulnerability is a weakness; risk factors in the likelihood and impact of its exploitation
Authentication vs. authorizationAuthentication proves identity; authorization decides what that identity may do; accounting records what it did
IDS vs. IPSIDS detects and alerts; IPS can actively block
Phishing vs. spear phishing vs. vishing vs. smishingBroad email lure, targeted email lure, voice-call lure and text-message lure
DRP vs. BCPDisaster recovery restores systems and data; business continuity keeps critical operations running through disruption
Active vs. passive reconnaissanceActive interacts with the target (such as port scanning); passive gathers information without touching it
Data in transit vs. at rest vs. in useMoving across a network, stored on media, or being processed in memory
Compliance acronyms: GDPR, HIPAA, PCI DSS, FERPA and FISMA each appear in the objectives, in endpoint and incident-handling contexts. You do not need legal depth, but you should associate each with the kind of data or organization it governs and understand that they can impose reporting and notification duties after an incident.

What the Credential Is For

The certification targets entry-level security and IT support roles, such as help desk and support technician positions with security responsibilities, junior security operations assistants and technicians who maintain endpoint and network hygiene. Because it is a foundation credential, it works best as a signal that you understand core concepts, paired with hands-on evidence such as lab work. For role types, see CCST-C jobs; for earning expectations, the CCST-C salary guide; and for a value judgment, whether the CCST-C is worth it.

When you are ready to test yourself under realistic conditions, our CCST-C practice tests mirror the five domains so you can find weak spots before exam day. You can also compare your readiness against the data in what is known about CCST-C pass rates, keeping in mind the limits of any published figures.

Frequently Asked Questions

How long is the CCST Cybersecurity exam and what does it cost?

Cisco lists exam 100-160 at 50 minutes with a fee of USD125. Always confirm current pricing and any regional differences on Cisco's exam page or the Certiport/Pearson VUE registration page before booking.

Are there official percentage weights for each domain?

The official objectives define five domains, but the sources used for this guide do not establish percentage weights. Treat all five as testable and study them evenly rather than trusting unofficial weight claims.

Is the 150 hours of preparation a mandatory prerequisite?

No. Cisco describes about 150 hours of instruction and hands-on experience as the preparation of a successful candidate, but it is not established as a required prerequisite. See the CCST-C requirements guide for details on eligibility.

Is this the same as CCST Networking or CyberOps Associate?

No. CCST Cybersecurity is a separate certification from CCST Networking and from Cisco CyberOps Associate. Each has its own objectives, so make sure the materials you study reference the Cybersecurity objectives specifically.

Which domain should I prioritize if I am short on time?

Because weights are not published, avoid skipping any domain. If you must prioritize, start with Domain 1 since its vocabulary underpins the rest, then spend extra time on hands-on tools in Domain 3 and the NIST 800-61 lifecycle in Domain 5, which reward concrete familiarity.

Ready to pass your CCST-C exam?

Put this into practice with free CCST-C questions across every exam domain.