1.1 About the Cisco CCST Cybersecurity Exam
Key Takeaways
- Cisco publishes exactly three hard parameters for the 100-160 exam: a 50-minute time limit, a US$125 price, and delivery in seven languages.
- Cisco does not publish CCST passing scores or a fixed item count; its policy states that passing scores are set by statistical analysis and may vary from exam to exam.
- The blueprint has five official domains and 23 numbered sub-topics (1.1-1.4, 2.1-2.5, 3.1-3.6, 4.1-4.4, 5.1-5.4), and Cisco publishes no percentage weight for any domain.
- CCST certifications earned on or after July 15, 2025 are valid for five years; those earned before that date remain valid for a lifetime.
- After a failed attempt you must wait five calendar days, beginning the day after the attempt, before retesting the same exam.
About the Cisco CCST Cybersecurity Exam
Quick Summary: The Cisco Certified Support Technician (CCST) Cybersecurity exam (exam code 100-160) is Cisco's entry-level security credential. It validates foundational knowledge across security principles, network security, endpoint security, vulnerability assessment and risk management, and incident handling. Cisco publishes three hard parameters: a 50-minute time limit, a US$125 price, and delivery in seven languages. Cisco deliberately does not publish the item count or the passing score. There are no prerequisites. Certifications earned on or after 15 July 2025 are valid for five years.
Executive Overview & Role in the Industry
The Cisco Certified Support Technician (CCST) Cybersecurity credential is Cisco's foundational entry point into the cybersecurity career pipeline. It is aimed at secondary and post-secondary students, career changers, IT help desk staff, and entry-level security analysts, and it bridges academic theory and practical operational security.
Cisco positions CCST Cybersecurity explicitly as a first step toward the Cisco CyberOps Associate (200-201) certification. That is the stated progression on Cisco's own exam page, and it differs from the other two CCST tracks (IT Support 100-140 and Networking 100-150), whose natural step-up is CCNA. Typical target roles are cybersecurity technician, junior/Tier 1 SOC analyst, IT security support specialist, and help desk with a security remit.
Unlike Cisco's associate-level tracks, the CCST Cybersecurity exam assumes no prior formal IT work experience and carries no formal prerequisites. Cisco recommends only that you understand the exam topics before booking.
What Cisco Actually Publishes — and What It Does Not
This distinction matters more on CCST than on almost any other entry-level certification, because third-party sites fill the gap with invented numbers. The table below separates confirmed Cisco policy from the unpublished values.
| Exam Parameter | Official Cisco Position |
|---|---|
| Full certification name | Cisco Certified Support Technician (CCST) Cybersecurity |
| Exam code | 100-160 |
| Time allowed | 50 minutes (published on Cisco's exam page) |
| Price | US$125 (published on Cisco's exam page) |
| Languages | English, Arabic, Chinese, Spanish, French, Japanese, Portuguese |
| Number of questions | Not published. Cisco's exam page lists only duration, price, and languages. Item counts can differ between exam forms. |
| Passing score | Not published. Cisco policy: "Cisco does not publish exam passing scores because exam questions and passing scores are subject to change and may vary exam to exam, without notice." Passing scores are set by statistical analysis. |
| Score reporting | Pass/fail, plus a performance breakout by exam section on the score report, so you can see which domains cost you points. |
| Item formats | Cisco does not publish an item-type breakdown for 100-160. Cisco written exams use multiple-choice single-answer and multiple-response items; Certiport offers a free Test Drive demo if you want to see the delivery interface before exam day. |
| Prerequisites | None |
| Delivery | Pearson VUE (test centre or OnVUE online proctoring) and Certiport (the academic and Cisco Networking Academy channel) |
| Credential validity | Five years if earned on or after 15 July 2025. Lifetime if earned before 15 July 2025. |
| Recertification | Pass any CCST, associate, professional, or expert Cisco certification exam. Continuing Education (CE) credits do not apply to CCST. |
| Retake after a fail | Five calendar days, beginning the day after the failed attempt, before retesting the same exam |
| Retake after a pass | 180 days before retaking the same exam number |
| Stated next step | Cisco CyberOps Associate (200-201) |
Why the unpublished numbers matter
Search for this exam and you will find confident claims of "45–50 questions," "a passing score of 700 out of 1,000," "750–850 scaled," and "80–85%." None of these come from Cisco. They conflict with one another precisely because they are estimates that got repeated until they looked official.
Two practical consequences for your preparation:
- Do not pace yourself against an assumed item count. Pace against the clock. Fifty minutes is the only fixed quantity, so check the on-screen question counter when your exam starts and divide the remaining time by the remaining items.
- Do not aim at a percentage. Because the cut score is set statistically and can move between forms, "I only need 70%" is an unsafe target. Aim for solid competence across all five domains — the section-level performance breakout on your score report exists precisely because Cisco expects balanced coverage.
The Five Official Exam Domains
Cisco organises the 100-160 blueprint into five domains containing 23 numbered sub-topics. Cisco publishes no percentage weight for any domain. Treat all five as examinable and study to the sub-topic list below — it is the actual contract for what can appear on the exam.
Domain 1: Essential Security Principles
| Sub-topic | Official scope |
|---|---|
| 1.1 Define essential security principles | Vulnerabilities, threats, exploits, and risks; attack vectors; hardening; defense-in-depth; confidentiality, integrity, and availability (CIA); types of attackers; reasons for attacks; code of ethics |
| 1.2 Explain common threats and vulnerabilities | Malware, ransomware, denial of service, botnets, social engineering attacks (tailgating, spear phishing, phishing, vishing, smishing), physical attacks, man-in-the-middle, IoT vulnerabilities, insider threats, advanced persistent threat (APT) |
| 1.3 Explain access management principles | Authentication, authorization, and accounting (AAA); RADIUS; multifactor authentication (MFA); password policies |
| 1.4 Explain encryption methods and applications | Types of encryption, hashing, certificates, public key infrastructure (PKI); strong vs. weak encryption algorithms; states of data and appropriate encryption (data in transit, at rest, in use); protocols that use encryption |
Domain 2: Basic Network Security Concepts
| Sub-topic | Official scope |
|---|---|
| 2.1 Describe TCP/IP protocol vulnerabilities | TCP, UDP, HTTP, ARP, ICMP, DHCP, DNS |
| 2.2 Explain how network addresses impact network security | IPv4 and IPv6 addresses, MAC addresses, network segmentation, CIDR notation, NAT, public vs. private networks |
| 2.3 Describe network infrastructure and technologies | Network security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS, IPS |
| 2.4 Set up a secure wireless SoHo network | MAC address filtering, encryption standards and protocols, SSID |
| 2.5 Implement secure access technologies | ACL, firewall, VPN, NAC |
Domain 3: Endpoint Security Concepts
| Sub-topic | Official scope |
|---|---|
| 3.1 Describe operating system security concepts | Windows, macOS, and Linux; security features including Windows Defender and host-based firewalls; CLI and PowerShell; file and directory permissions; privilege escalation |
| 3.2 Demonstrate familiarity with endpoint tools that gather security assessment information | netstat, nslookup, tcpdump |
| 3.3 Verify that endpoint systems meet security policies and standards | Hardware inventory (asset management), software inventory, program deployment, data backups, regulatory compliance (PCI DSS, HIPAA, GDPR), BYOD (device management, data encryption, app distribution, configuration management) |
| 3.4 Implement software and hardware updates | Windows Update, application updates, device drivers, firmware, patching |
| 3.5 Interpret system logs | Event Viewer, audit logs, system and application logs, syslog, identification of anomalies |
| 3.6 Demonstrate familiarity with malware removal | Scanning systems, reviewing scan logs, malware remediation |
Domain 4: Vulnerability Assessment and Risk Management
| Sub-topic | Official scope |
|---|---|
| 4.1 Explain vulnerability management | Vulnerability identification, management, and mitigation; active and passive reconnaissance; testing (port scanning, automation) |
| 4.2 Use threat intelligence techniques to identify potential network vulnerabilities | Uses and limitations of vulnerability databases; industry-standard assessment tools, policies, and reports; CVEs, cybersecurity reports and news, subscription services, collective intelligence; ad hoc and automated threat intelligence; updating documentation proactively before, during, and after incidents; how to secure, share, and update documentation |
| 4.3 Explain risk management | Vulnerability vs. risk, ranking risks, approaches to risk management, risk mitigation strategies, levels of risk (low, medium, high, extremely high), risks associated with specific data types and classifications, security assessments of IT systems |
| 4.4 Explain the importance of disaster recovery and business continuity planning | Natural and human-caused disasters; features of disaster recovery plans (DRP) and business continuity plans (BCP); backup; disaster recovery controls (detective, preventive, and corrective) |
Domain 5: Incident Handling
| Sub-topic | Official scope |
|---|---|
| 5.1 Monitor security events and know when escalation is required | Role of SIEM and SOAR; monitoring network data to identify security incidents (packet captures, log file entries); identifying suspicious events as they occur |
| 5.2 Explain digital forensics and attack attribution processes | Cyber Kill Chain, MITRE ATT&CK Matrix, and Diamond Model; tactics, techniques, and procedures (TTP); sources of evidence (artifacts); evidence handling (preserving digital evidence, chain of custody) |
| 5.3 Explain the impact of compliance frameworks on incident handling | Compliance frameworks (GDPR, HIPAA, PCI-DSS, FERPA, FISMA); reporting and notification requirements |
| 5.4 Describe the elements of cybersecurity incident response | Policy, plan, and procedure elements; incident response lifecycle stages (NIST Special Publication 800-61, sections 2.3 and 3.1–3.4) |
Note the explicit citation in 5.4. Cisco points at sections 2.3 and 3.1–3.4 of NIST SP 800-61, which is the section numbering of Revision 2 and its four-phase lifecycle. NIST superseded Rev. 2 with Rev. 3 in April 2025, which replaces the four-phase model with a mapping to the CSF 2.0 functions. Learn the Rev. 2 four-phase lifecycle for this exam, and know that Rev. 3 exists for real-world work. Section 6.1 covers both.
Comparative Credential Matrix
Where CCST Cybersecurity sits relative to the two credentials it is most often compared against:
| Feature / Metric | Cisco CCST Cybersecurity (100-160) | CompTIA Security+ (SY0-701) | Cisco CyberOps Associate (200-201) |
|---|---|---|---|
| Target audience | Entry level: students, career changers, help desk | Early-career security professionals | Associate SOC analysts and security engineers |
| Prerequisites | None | None formally; ~2 years of IT/security experience recommended | None formally; networking and security fundamentals recommended |
| Time limit | 50 minutes | 90 minutes | 120 minutes |
| Question count | Not published by Cisco | Maximum 90 (published by CompTIA) | Not published by Cisco |
| Passing score | Not published by Cisco | 750 on a 100–900 scale (published by CompTIA) | Not published by Cisco |
| Exam price | US$125 | ~US$425 list; CompTIA raised list pricing in 2025 and again in mid-2026, so confirm at checkout | ~US$300 |
| Validity & renewal | 5 years (earned on/after 15 Jul 2025); renew by passing any CCST or higher Cisco exam. CE credits do not apply. | 3 years; renew with 50 CEUs or by retaking | 3 years; renew by exam or Cisco CE credits |
| Scope | Cisco entry-level security foundation | Vendor-neutral, widely requested in job postings | Cisco SOC and security-operations focus |
Security+ carries more weight in job listings today; CCST Cybersecurity is materially cheaper, shorter, and has no experience expectation, which makes it a sensible first credential rather than a substitute.
Examination Administration & Testing Policies
The 100-160 exam is delivered through two Cisco-authorised channels:
- Pearson VUE — the route for most commercial and self-funded candidates. Test at a physical Pearson VUE centre or remotely through OnVUE online proctoring.
- Certiport — the academic channel used by high schools, community colleges, universities, and Cisco Networking Academy programs. Academic candidates commonly test in a proctored school lab or through Certiport's remote option.
Online proctoring guidelines
When testing remotely, expect the standard proctored-exam environment rules:
- Private workspace. A walled room with a closed door, no other people, and no interruptions.
- Identity verification. A valid, unexpired government-issued photo ID.
- Clear desk. No secondary monitors, phones, smartwatches, notes, scrap paper, or writing implements unless an approved accommodation applies.
- Continuous monitoring. Webcam and microphone stay on for the whole session.
- Pre-flight system test. Run the OnVUE or Certiport system check ahead of exam day, not on the morning of.
Retake and validity policy
- After a failed attempt: Cisco requires a wait of five (5) calendar days, beginning the day after the failed attempt, before you may retest the same exam. This is the same rule Cisco applies to entry, associate, professional, specialist, and CCDE written exams. There is no published cap on total attempts, and each attempt costs the full fee.
- After a passed attempt: you may not retake the same exam number for 180 days.
- Credential validity: Cisco's exam policy states that "exams for Cisco Certified Support Technician (CCST) entry-level certifications are valid for five years from the date you pass." Cisco's CCST FAQ adds the cut-over: certifications earned before 15 July 2025 remain valid for a lifetime; certifications earned on or after 15 July 2025 are valid for five years.
- How to recertify: pass any CCST, associate, professional, or expert Cisco certification exam before your expiry date. Continuing Education credits cannot be applied to CCST recertification — this is the main way CCST renewal differs from CCNA renewal.
Watch for stale guidance. A large volume of CCST material published in 2023 and 2024 still says the credential "never expires." That was accurate then and is no longer accurate for anyone certifying today.
Which exam parameters does Cisco actually publish for the CCST Cybersecurity 100-160 exam?
How does Cisco weight the five CCST Cybersecurity exam domains?
A candidate passes the CCST Cybersecurity exam in 2026. How long is the certification valid, and how is it renewed?
A candidate fails the CCST Cybersecurity exam on a Monday. Under Cisco policy, what is the earliest they may retest the same exam?
Cisco identifies which certification as the stated next step after CCST Cybersecurity?