1.1 About the Cisco CCST Cybersecurity Exam

Key Takeaways

  • Cisco publishes exactly three hard parameters for the 100-160 exam: a 50-minute time limit, a US$125 price, and delivery in seven languages.
  • Cisco does not publish CCST passing scores or a fixed item count; its policy states that passing scores are set by statistical analysis and may vary from exam to exam.
  • The blueprint has five official domains and 23 numbered sub-topics (1.1-1.4, 2.1-2.5, 3.1-3.6, 4.1-4.4, 5.1-5.4), and Cisco publishes no percentage weight for any domain.
  • CCST certifications earned on or after July 15, 2025 are valid for five years; those earned before that date remain valid for a lifetime.
  • After a failed attempt you must wait five calendar days, beginning the day after the attempt, before retesting the same exam.
Last updated: August 2026

About the Cisco CCST Cybersecurity Exam

Quick Summary: The Cisco Certified Support Technician (CCST) Cybersecurity exam (exam code 100-160) is Cisco's entry-level security credential. It validates foundational knowledge across security principles, network security, endpoint security, vulnerability assessment and risk management, and incident handling. Cisco publishes three hard parameters: a 50-minute time limit, a US$125 price, and delivery in seven languages. Cisco deliberately does not publish the item count or the passing score. There are no prerequisites. Certifications earned on or after 15 July 2025 are valid for five years.


Executive Overview & Role in the Industry

The Cisco Certified Support Technician (CCST) Cybersecurity credential is Cisco's foundational entry point into the cybersecurity career pipeline. It is aimed at secondary and post-secondary students, career changers, IT help desk staff, and entry-level security analysts, and it bridges academic theory and practical operational security.

Cisco positions CCST Cybersecurity explicitly as a first step toward the Cisco CyberOps Associate (200-201) certification. That is the stated progression on Cisco's own exam page, and it differs from the other two CCST tracks (IT Support 100-140 and Networking 100-150), whose natural step-up is CCNA. Typical target roles are cybersecurity technician, junior/Tier 1 SOC analyst, IT security support specialist, and help desk with a security remit.

Unlike Cisco's associate-level tracks, the CCST Cybersecurity exam assumes no prior formal IT work experience and carries no formal prerequisites. Cisco recommends only that you understand the exam topics before booking.


What Cisco Actually Publishes — and What It Does Not

This distinction matters more on CCST than on almost any other entry-level certification, because third-party sites fill the gap with invented numbers. The table below separates confirmed Cisco policy from the unpublished values.

Exam ParameterOfficial Cisco Position
Full certification nameCisco Certified Support Technician (CCST) Cybersecurity
Exam code100-160
Time allowed50 minutes (published on Cisco's exam page)
PriceUS$125 (published on Cisco's exam page)
LanguagesEnglish, Arabic, Chinese, Spanish, French, Japanese, Portuguese
Number of questionsNot published. Cisco's exam page lists only duration, price, and languages. Item counts can differ between exam forms.
Passing scoreNot published. Cisco policy: "Cisco does not publish exam passing scores because exam questions and passing scores are subject to change and may vary exam to exam, without notice." Passing scores are set by statistical analysis.
Score reportingPass/fail, plus a performance breakout by exam section on the score report, so you can see which domains cost you points.
Item formatsCisco does not publish an item-type breakdown for 100-160. Cisco written exams use multiple-choice single-answer and multiple-response items; Certiport offers a free Test Drive demo if you want to see the delivery interface before exam day.
PrerequisitesNone
DeliveryPearson VUE (test centre or OnVUE online proctoring) and Certiport (the academic and Cisco Networking Academy channel)
Credential validityFive years if earned on or after 15 July 2025. Lifetime if earned before 15 July 2025.
RecertificationPass any CCST, associate, professional, or expert Cisco certification exam. Continuing Education (CE) credits do not apply to CCST.
Retake after a failFive calendar days, beginning the day after the failed attempt, before retesting the same exam
Retake after a pass180 days before retaking the same exam number
Stated next stepCisco CyberOps Associate (200-201)

Why the unpublished numbers matter

Search for this exam and you will find confident claims of "45–50 questions," "a passing score of 700 out of 1,000," "750–850 scaled," and "80–85%." None of these come from Cisco. They conflict with one another precisely because they are estimates that got repeated until they looked official.

Two practical consequences for your preparation:

  1. Do not pace yourself against an assumed item count. Pace against the clock. Fifty minutes is the only fixed quantity, so check the on-screen question counter when your exam starts and divide the remaining time by the remaining items.
  2. Do not aim at a percentage. Because the cut score is set statistically and can move between forms, "I only need 70%" is an unsafe target. Aim for solid competence across all five domains — the section-level performance breakout on your score report exists precisely because Cisco expects balanced coverage.

The Five Official Exam Domains

Cisco organises the 100-160 blueprint into five domains containing 23 numbered sub-topics. Cisco publishes no percentage weight for any domain. Treat all five as examinable and study to the sub-topic list below — it is the actual contract for what can appear on the exam.

Domain 1: Essential Security Principles

Sub-topicOfficial scope
1.1 Define essential security principlesVulnerabilities, threats, exploits, and risks; attack vectors; hardening; defense-in-depth; confidentiality, integrity, and availability (CIA); types of attackers; reasons for attacks; code of ethics
1.2 Explain common threats and vulnerabilitiesMalware, ransomware, denial of service, botnets, social engineering attacks (tailgating, spear phishing, phishing, vishing, smishing), physical attacks, man-in-the-middle, IoT vulnerabilities, insider threats, advanced persistent threat (APT)
1.3 Explain access management principlesAuthentication, authorization, and accounting (AAA); RADIUS; multifactor authentication (MFA); password policies
1.4 Explain encryption methods and applicationsTypes of encryption, hashing, certificates, public key infrastructure (PKI); strong vs. weak encryption algorithms; states of data and appropriate encryption (data in transit, at rest, in use); protocols that use encryption

Domain 2: Basic Network Security Concepts

Sub-topicOfficial scope
2.1 Describe TCP/IP protocol vulnerabilitiesTCP, UDP, HTTP, ARP, ICMP, DHCP, DNS
2.2 Explain how network addresses impact network securityIPv4 and IPv6 addresses, MAC addresses, network segmentation, CIDR notation, NAT, public vs. private networks
2.3 Describe network infrastructure and technologiesNetwork security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS, IPS
2.4 Set up a secure wireless SoHo networkMAC address filtering, encryption standards and protocols, SSID
2.5 Implement secure access technologiesACL, firewall, VPN, NAC

Domain 3: Endpoint Security Concepts

Sub-topicOfficial scope
3.1 Describe operating system security conceptsWindows, macOS, and Linux; security features including Windows Defender and host-based firewalls; CLI and PowerShell; file and directory permissions; privilege escalation
3.2 Demonstrate familiarity with endpoint tools that gather security assessment informationnetstat, nslookup, tcpdump
3.3 Verify that endpoint systems meet security policies and standardsHardware inventory (asset management), software inventory, program deployment, data backups, regulatory compliance (PCI DSS, HIPAA, GDPR), BYOD (device management, data encryption, app distribution, configuration management)
3.4 Implement software and hardware updatesWindows Update, application updates, device drivers, firmware, patching
3.5 Interpret system logsEvent Viewer, audit logs, system and application logs, syslog, identification of anomalies
3.6 Demonstrate familiarity with malware removalScanning systems, reviewing scan logs, malware remediation

Domain 4: Vulnerability Assessment and Risk Management

Sub-topicOfficial scope
4.1 Explain vulnerability managementVulnerability identification, management, and mitigation; active and passive reconnaissance; testing (port scanning, automation)
4.2 Use threat intelligence techniques to identify potential network vulnerabilitiesUses and limitations of vulnerability databases; industry-standard assessment tools, policies, and reports; CVEs, cybersecurity reports and news, subscription services, collective intelligence; ad hoc and automated threat intelligence; updating documentation proactively before, during, and after incidents; how to secure, share, and update documentation
4.3 Explain risk managementVulnerability vs. risk, ranking risks, approaches to risk management, risk mitigation strategies, levels of risk (low, medium, high, extremely high), risks associated with specific data types and classifications, security assessments of IT systems
4.4 Explain the importance of disaster recovery and business continuity planningNatural and human-caused disasters; features of disaster recovery plans (DRP) and business continuity plans (BCP); backup; disaster recovery controls (detective, preventive, and corrective)

Domain 5: Incident Handling

Sub-topicOfficial scope
5.1 Monitor security events and know when escalation is requiredRole of SIEM and SOAR; monitoring network data to identify security incidents (packet captures, log file entries); identifying suspicious events as they occur
5.2 Explain digital forensics and attack attribution processesCyber Kill Chain, MITRE ATT&CK Matrix, and Diamond Model; tactics, techniques, and procedures (TTP); sources of evidence (artifacts); evidence handling (preserving digital evidence, chain of custody)
5.3 Explain the impact of compliance frameworks on incident handlingCompliance frameworks (GDPR, HIPAA, PCI-DSS, FERPA, FISMA); reporting and notification requirements
5.4 Describe the elements of cybersecurity incident responsePolicy, plan, and procedure elements; incident response lifecycle stages (NIST Special Publication 800-61, sections 2.3 and 3.1–3.4)

Note the explicit citation in 5.4. Cisco points at sections 2.3 and 3.1–3.4 of NIST SP 800-61, which is the section numbering of Revision 2 and its four-phase lifecycle. NIST superseded Rev. 2 with Rev. 3 in April 2025, which replaces the four-phase model with a mapping to the CSF 2.0 functions. Learn the Rev. 2 four-phase lifecycle for this exam, and know that Rev. 3 exists for real-world work. Section 6.1 covers both.


Comparative Credential Matrix

Where CCST Cybersecurity sits relative to the two credentials it is most often compared against:

Feature / MetricCisco CCST Cybersecurity (100-160)CompTIA Security+ (SY0-701)Cisco CyberOps Associate (200-201)
Target audienceEntry level: students, career changers, help deskEarly-career security professionalsAssociate SOC analysts and security engineers
PrerequisitesNoneNone formally; ~2 years of IT/security experience recommendedNone formally; networking and security fundamentals recommended
Time limit50 minutes90 minutes120 minutes
Question countNot published by CiscoMaximum 90 (published by CompTIA)Not published by Cisco
Passing scoreNot published by Cisco750 on a 100–900 scale (published by CompTIA)Not published by Cisco
Exam priceUS$125~US$425 list; CompTIA raised list pricing in 2025 and again in mid-2026, so confirm at checkout~US$300
Validity & renewal5 years (earned on/after 15 Jul 2025); renew by passing any CCST or higher Cisco exam. CE credits do not apply.3 years; renew with 50 CEUs or by retaking3 years; renew by exam or Cisco CE credits
ScopeCisco entry-level security foundationVendor-neutral, widely requested in job postingsCisco SOC and security-operations focus

Security+ carries more weight in job listings today; CCST Cybersecurity is materially cheaper, shorter, and has no experience expectation, which makes it a sensible first credential rather than a substitute.


Examination Administration & Testing Policies

The 100-160 exam is delivered through two Cisco-authorised channels:

  • Pearson VUE — the route for most commercial and self-funded candidates. Test at a physical Pearson VUE centre or remotely through OnVUE online proctoring.
  • Certiport — the academic channel used by high schools, community colleges, universities, and Cisco Networking Academy programs. Academic candidates commonly test in a proctored school lab or through Certiport's remote option.

Online proctoring guidelines

When testing remotely, expect the standard proctored-exam environment rules:

  1. Private workspace. A walled room with a closed door, no other people, and no interruptions.
  2. Identity verification. A valid, unexpired government-issued photo ID.
  3. Clear desk. No secondary monitors, phones, smartwatches, notes, scrap paper, or writing implements unless an approved accommodation applies.
  4. Continuous monitoring. Webcam and microphone stay on for the whole session.
  5. Pre-flight system test. Run the OnVUE or Certiport system check ahead of exam day, not on the morning of.

Retake and validity policy

  • After a failed attempt: Cisco requires a wait of five (5) calendar days, beginning the day after the failed attempt, before you may retest the same exam. This is the same rule Cisco applies to entry, associate, professional, specialist, and CCDE written exams. There is no published cap on total attempts, and each attempt costs the full fee.
  • After a passed attempt: you may not retake the same exam number for 180 days.
  • Credential validity: Cisco's exam policy states that "exams for Cisco Certified Support Technician (CCST) entry-level certifications are valid for five years from the date you pass." Cisco's CCST FAQ adds the cut-over: certifications earned before 15 July 2025 remain valid for a lifetime; certifications earned on or after 15 July 2025 are valid for five years.
  • How to recertify: pass any CCST, associate, professional, or expert Cisco certification exam before your expiry date. Continuing Education credits cannot be applied to CCST recertification — this is the main way CCST renewal differs from CCNA renewal.

Watch for stale guidance. A large volume of CCST material published in 2023 and 2024 still says the credential "never expires." That was accurate then and is no longer accurate for anyone certifying today.

Loading diagram...
CCST Cybersecurity (100-160) Blueprint: Five Domains and 23 Sub-Topics
Test Your Knowledge

Which exam parameters does Cisco actually publish for the CCST Cybersecurity 100-160 exam?

A
B
C
D
Test Your Knowledge

How does Cisco weight the five CCST Cybersecurity exam domains?

A
B
C
D
Test Your Knowledge

A candidate passes the CCST Cybersecurity exam in 2026. How long is the certification valid, and how is it renewed?

A
B
C
D
Test Your Knowledge

A candidate fails the CCST Cybersecurity exam on a Monday. Under Cisco policy, what is the earliest they may retest the same exam?

A
B
C
D
Test Your Knowledge

Cisco identifies which certification as the stated next step after CCST Cybersecurity?

A
B
C
D