Cisco CCST 100-160 Cybersecurity Certification Exam

Cisco Certified Support Technician Cybersecurity 100-160

The Cisco CCST 100-160 Cybersecurity certification validates entry-level knowledge of cybersecurity concepts and support tasks. The exam covers essential security principles, basic network security concepts, endpoint security concepts, vulnerability assessment and risk management, and incident handling. Candidates demonstrate knowledge of the CIA triad, common threats, access management, encryption, firewalls, VPNs, IDS and IPS, operating system security, system logs, malware removal, vulnerability management, and the NIST SP 800-61 incident response lifecycle. The exam consists of 50 questions over 50 minutes, with an 80% passing score.

Certification Overview

  • Exam name: CCST 100-160 Cybersecurity
  • Vendor: Cisco
  • Exam code: 100-160
  • Duration: 50 minutes
  • Total questions: 50
  • Passing score: 80%

Who Should Take This Exam?

Cybersecurity Support Technician, Entry-level Cybersecurity Analyst, SOC Analyst, Help Desk Technician, IT Support Specialist, Junior Network Technician, Systems Administrator, Security Operations Assistant

Prerequisites

No formal prerequisites; basic familiarity with computer systems, networking fundamentals, and security terminology is recommended.

Topics Covered

  • Topics to be announced

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop

CCST 100-160 Cybersecurity Practice Questions

Our question bank contains 864+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

Essential Security Principles

Which principle of the CIA triad is violated when an attacker modifies a file's contents without authorization, while the file remains accessible to legitimate users?
  • Availability
  • Integrity
  • Confidentiality
  • Accountability
What does hardening a device primarily involve?
  • Disabling unnecessary services, closing unused ports, and applying secure configuration baselines
  • Increasing the device's processing power to handle more network traffic
  • Installing additional user applications for employee convenience
  • Encrypting all outbound network traffic by default
An email that appears to come from a bank and asks the recipient to click a link and enter account credentials on a fake website is an example of which attack?
  • Vishing
  • Smishing
  • Phishing
  • Tailgating

Basic Network Security Concepts

Which sequence of TCP flags correctly represents the standard three-way handshake used to establish a connection?
  • SYN, SYN-ACK, ACK
  • ACK, SYN, FIN
  • SYN, ACK, FIN-ACK
  • SYN-ACK, SYN, RST
What is the primary purpose of the Address Resolution Protocol (ARP)?
  • Translate domain names into IP addresses
  • Resolve a known IP address to its corresponding MAC address on the local segment
  • Assign IP addresses dynamically to hosts
  • Encrypt traffic between two hosts on the same subnet
By default, DNS queries and responses primarily use which transport-layer port?
  • Port 53
  • Port 67
  • Port 161
  • Port 389

Endpoint Security Concepts

Which Windows built-in feature provides real-time protection against viruses and malware without requiring a third-party install?
  • Windows Defender
  • BitLocker
  • Group Policy Editor
  • Task Scheduler
What is the primary purpose of a host-based firewall?
  • Encrypt files stored on the local disk
  • Filter inbound and outbound network traffic on a single device
  • Back up user data to the cloud automatically
  • Manage local user account passwords
Which command-line tool is used on Windows to display active network connections and listening ports?
  • nslookup
  • tcpdump
  • netstat
  • chkdsk

Vulnerability Assessment and Risk Management

What is the term for gathering information about a target system without directly interacting with it, such as reviewing public DNS records or job postings?
  • Active reconnaissance
  • Passive reconnaissance
  • Penetration testing
  • Vulnerability scanning
Which type of port scan completes the full TCP three-way handshake with the target port?
  • SYN (half-open) scan
  • Full connect (TCP connect) scan
  • FIN scan
  • Null scan
Which organization assigns and maintains the standardized CVE identifiers used to catalog publicly known vulnerabilities?
  • NIST
  • ISO
  • MITRE
  • ISACA

Incident Handling

What is the primary function of a SIEM platform in a security operations center?
  • Aggregate and correlate log and event data from multiple sources for analysis and alerting
  • Automatically patch vulnerable operating systems across the network
  • Encrypt data in transit between branch offices
  • Replace firewalls by filtering traffic at the network perimeter
Which term describes the pieces of digital evidence, such as log entries and memory dumps, collected during an investigation?
  • Artifacts
  • Signatures
  • Baselines
  • Heuristics
Under GDPR, within how many hours of becoming aware of a personal data breach must a data controller generally notify the relevant supervisory authority?
  • 24 hours
  • 72 hours
  • 7 days
  • 30 days

Frequently Asked Questions

How many questions are on the exam?

The CCST 100-160 Cybersecurity exam contains 50 questions.

What is the passing score?

You need 80% to pass.

How long is the exam?

You have 50 minutes to complete the exam.

Practice with realistic mock exams to prepare for your Cisco certification.