Cisco · Practice Exam · Entry-level · CCST · Updated for 2026

Cisco 100-160 CCST Cybersecurity Practice Exam

Cover every objective area on Cisco’s CCST Cybersecurity exam — essential security principles, basic network security, endpoint security, vulnerability assessment and risk management, and incident handling — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

100-160 exam at a glance

Vendor
Cisco
Exam code
100-160
Certification
Cisco Certified Support Technician (CCST) Cybersecurity
Level
Entry-level (foundational)
Family
One of three CCST exams — IT Support (100-140), Networking (100-150), Cybersecurity (100-160)
Duration
50 minutes
Scoring
Reported as pass/fail; Cisco does not publish a public numeric cut score; question count varies by exam form
Domains
Five objective areas (see below); Cisco does not publish fixed percentage weights for CCST
Prerequisites
None. Aimed at students, interns, and entry-level IT and cybersecurity staff
Next step
Cisco CyberOps Associate (200-201) — the stated security pathway beyond CCST Cybersecurity
Delivery
Pearson VUE or Certiport; test center or online proctored
Validity
Earned on/after July 15, 2025: valid 5 years. Earned before that date: lifetime. Confirm with Cisco

Sources: Cisco — CCST Cybersecurity (100-160) exam page · Cisco Learning Network — CCST Cybersecurity exam topics. Verify current details with Cisco before scheduling.

About the Cisco CCST Cybersecurity (100-160) certification

The 100-160 exam earns the Cisco Certified Support Technician (CCST) Cybersecurity certification — an entry-level credential that validates foundational security knowledge: core principles, common threats and vulnerabilities, protecting endpoints and networks, assessing risk, and responding to incidents. It’s aimed at people starting a cybersecurity or security-support career. For how certification exams work generally, see the certification study guides in our Learning Hub.

CCST Cybersecurity is one of three CCST exams — IT Support (100-140), Networking (100-150), and Cybersecurity (100-160). Unlike the other two, whose natural step-up is CCNA, the stated next step from CCST Cybersecurity is Cisco’s CyberOps Associate (200-201). There are no prerequisites, and Cisco pitches it at students, interns, and entry-level IT and security staff.

Every PowerKram practice question maps to one of the exam’s objective areas and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.

100-160 exam domains

Cisco organizes the CCST Cybersecurity exam into five objective areas. Cisco publishes the objectives but not a fixed percentage weight for each, so rather than invent numbers we list the areas and describe what each covers. Incident handling and endpoint security reflect real support priorities, but all five areas are tested — build breadth across the whole blueprint. Confirm the current objectives on Cisco’s exam page.

Essential Security Principles

Vulnerabilities, threats, exploits, and risks; attack vectors; hardening and defense-in-depth; the CIA triad (confidentiality, integrity, availability); types of attackers and motivations; and the security code of ethics.

Objective area
Basic Network Security Concepts

TCP/IP and protocol vulnerabilities, network device security, firewalls and network segmentation, and secure versus insecure protocols as perimeter defenses.

Objective area
Endpoint Security Concepts

Malware and ransomware, host-based protections such as antivirus and host firewalls, operating-system hardening, and securing the individual devices users work on.

Objective area
Vulnerability Assessment & Risk Management

Identifying and assessing vulnerabilities, understanding risk, security frameworks and compliance basics, and prioritizing remediation appropriately.

Objective area
Incident Handling

Security monitoring and logging, the incident-response process, basic digital-forensics awareness, and the support technician’s role in detecting and responding to security events.

Objective area

Source: Cisco Learning Network — CCST Cybersecurity (100-160) exam topics. Cisco does not publish a fixed percentage for each area, so none is shown here. Verify the current objectives before scheduling.

Who the 100-160 exam is for

CCST Cybersecurity is built for people starting out in security:

  • Students and interns entering IT and cybersecurity with a recognized first credential.
  • Entry-level security and support staff who want to prove foundational security knowledge.
  • Help-desk and desktop technicians moving toward security-focused roles.
  • Aspiring CyberOps candidates who want an approachable first step before associate-level security operations.

Its CCST siblings let you branch by interest: CCST IT Support (100-140) leans toward help-desk and desktop troubleshooting and CCST Networking (100-150) toward network fundamentals. When you’re ready to go deeper into security, CyberOps Associate (200-201) is the stated next step. For where security skills lead, see the cybersecurity and IT career paths in our Career Hub.

What this 100-160 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for cementing threat, endpoint, and incident-response concepts.

Exam mode

Timed, full-length simulation across the five objective areas at the real 50-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own CCST Cybersecurity exam material, so you can verify security principles, network and endpoint defense, and incident-handling concepts against the source.

Score by objective area

Results break down across the five areas so you can see whether it’s security principles, network security, endpoint security, vulnerability/risk, or incident handling that needs more work.

Sample 100-160 practice questions

Ten free questions across the CCST Cybersecurity objective areas, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.

Question 1 · Essential Security Principles

The “CIA triad” in cybersecurity stands for which three properties?

  1. Confidentiality, integrity, and availability
  2. Control, isolation, and auditing
  3. Cryptography, identity, and access
  4. Compliance, insurance, and assurance
Show answer & explanation

Correct: A. The CIA triad is the foundational security model: confidentiality (keeping data private), integrity (keeping it accurate and unaltered), and availability (keeping it accessible when needed).

Why not the others: control/isolation/auditing (B), cryptography/identity/access (C), and compliance/insurance/assurance (D) string together plausible-sounding security words, but none is the CIA triad Cisco defines.

Source: Cisco — CCST Cybersecurity: essential security principles → Further reading: PowerKram — CyberOps Associate (200-201) →
Question 2 · Essential Security Principles

Which term describes layering multiple, independent security controls so that no single failure exposes the system?

  1. Single sign-on
  2. Defense-in-depth
  3. Plaintext storage
  4. Port forwarding
Show answer & explanation

Correct: B — defense-in-depth. Defense-in-depth stacks independent controls (physical, network, endpoint, application, policy) so that if one layer is bypassed, others still protect the asset.

Why not the others: single sign-on (A) is an authentication convenience, plaintext storage (C) is a weakness, and port forwarding (D) is a networking function — none is the layered-defense concept.

Source: Cisco — CCST Cybersecurity: hardening & defense-in-depth → Further reading: PowerKram — CCST Networking (100-150) →
Question 3 · Endpoint Security

Which type of malware encrypts a victim’s files and demands payment for their release?

  1. Adware
  2. A cookie
  3. Ransomware
  4. A CAPTCHA
Show answer & explanation

Correct: C — ransomware. Ransomware encrypts files (or whole systems) and demands a ransom for the decryption key, making reliable backups and user awareness key defenses.

Why not the others: adware (A) displays unwanted ads, a cookie (B) stores small web-session data, and a CAPTCHA (D) is a bot-detection challenge — none holds files for ransom.

Source: Cisco — CCST Cybersecurity: malware & endpoint security → Further reading: PowerKram — CCST IT Support (100-140) →
Question 4 · Essential Security Principles

An attacker sends a targeted email impersonating a manager to trick an employee into transferring funds. What is this?

  1. A firmware update
  2. A spear-phishing (social-engineering) attack
  3. A routine backup
  4. A load-balancing event
Show answer & explanation

Correct: B. Spear phishing is a targeted social-engineering attack that impersonates a trusted party to manipulate a specific victim — a core threat category in the CCST objectives.

Why not the others: a firmware update (A), a backup (C), and a load-balancing event (D) are normal IT activities, not attacks.

Source: Cisco — CCST Cybersecurity: social-engineering threats →
Question 5 · Basic Network Security

Which device is primarily used to filter traffic between networks based on a set of security rules?

  1. A firewall
  2. A label printer
  3. A webcam
  4. A docking station
Show answer & explanation

Correct: A — a firewall. A firewall enforces security rules on traffic passing between networks (or network segments), allowing or blocking flows to protect the perimeter and internal zones.

Why not the others: a label printer (B), a webcam (C), and a docking station (D) have no traffic-filtering role.

Source: Cisco — CCST Cybersecurity: network security concepts → Further reading: PowerKram — CCST Networking (100-150) →
Question 6 · Vulnerability & Risk

In risk terms, what is a “vulnerability”?

  1. A guaranteed financial loss
  2. A type of firewall rule
  3. A brand of antivirus
  4. A weakness that a threat could exploit
Show answer & explanation

Correct: D. A vulnerability is a weakness (in software, configuration, or process) that a threat can exploit. Risk combines the likelihood of exploitation with the impact if it occurs.

Why not the others: it isn’t a guaranteed loss (A), a firewall rule (B), or an antivirus brand (C).

Source: Cisco — CCST Cybersecurity: vulnerabilities & risk →
Question 7 · Endpoint Security

Which practice most directly reduces the risk from known software vulnerabilities on endpoints?

  1. Disabling the screen saver
  2. Increasing monitor brightness
  3. Applying security patches and updates promptly
  4. Using a larger mouse pad
Show answer & explanation

Correct: C. Timely patching closes known vulnerabilities before attackers can exploit them, making patch and update management one of the highest-value endpoint defenses.

Why not the others: screen-saver settings (A), brightness (B), and a mouse pad (D) have no effect on vulnerability exposure.

Source: Cisco — CCST Cybersecurity: endpoint hardening →
Question 8 · Incident Handling

What is the main purpose of security logging and monitoring?

  1. To slow the network down deliberately
  2. To detect, investigate, and respond to suspicious or malicious activity
  3. To increase electricity use
  4. To replace the need for firewalls
Show answer & explanation

Correct: B. Logging and monitoring provide the visibility needed to detect anomalies, investigate incidents, and respond — the foundation of incident handling and security operations.

Why not the others: monitoring isn’t meant to slow the network (A) or raise power use (C), and it complements rather than replaces firewalls (D).

Source: Cisco — CCST Cybersecurity: monitoring & incident handling → Further reading: PowerKram — CyberOps Associate (200-201) →
Question 9 · Incident Handling

During a suspected security incident, why is preserving logs and evidence important?

  1. It automatically removes the malware
  2. It speeds up the internet connection
  3. It is never necessary
  4. It supports investigation, root-cause analysis, and any later forensic or legal needs
Show answer & explanation

Correct: D. Preserving logs and evidence lets responders reconstruct what happened, find the root cause, and support any forensic or legal follow-up — a core incident-handling responsibility.

Why not the others: preserving evidence doesn’t remove malware (A) or affect connection speed (B), and it is frequently necessary, not never (C).

Source: Cisco — CCST Cybersecurity: incident response & forensics →
Question 10 · Basic Network Security

Why is using an encrypted protocol such as HTTPS preferable to plain HTTP?

  1. It makes web pages larger
  2. It changes the website’s language
  3. It protects data in transit from eavesdropping and tampering
  4. It disables the firewall
Show answer & explanation

Correct: C. HTTPS encrypts traffic between client and server, protecting it from eavesdropping and tampering in transit — a clear example of choosing secure over insecure protocols.

Why not the others: HTTPS isn’t about page size (A) or language (B), and it does not disable the firewall (D).

Source: Cisco — CCST Cybersecurity: secure protocols →

Keep going: Learning & Career resources

CCST Cybersecurity is a launchpad — into the other CCST tracks, toward CyberOps, and into entry-level security roles. Two PowerKram hubs back this exam.

Deep dive: 100-160 scope, the security pathway, and study path

Where 100-160 sits

CCST Cybersecurity is an entry point with no prerequisites — a modern first step into security. It sits alongside CCST IT Support and CCST Networking, but its onward path is security-specific: the stated next step is Cisco CyberOps Associate, not CCNA. Pick Cybersecurity if security operations and defense is your target. See CyberOps Associate (200-201) →

The five objective areas

Essential security principles, basic network security, endpoint security, vulnerability assessment and risk management, and incident handling. Cisco doesn’t publish per-area percentages, so build breadth across all five — incident handling and endpoint security map closely to real support work, so give them solid, practical attention. See CCST IT Support (100-140) →

Realistic study path

Most candidates prepare in a few weeks. Learn the vocabulary precisely (threats vs vulnerabilities vs risk; confidentiality vs integrity vs availability), get comfortable recognizing common attacks and defenses, and practice thinking through a basic incident-response sequence. Finish with objective-mapped practice questions and one timed run at the 50-minute pace. Note the validity change: CCST certifications earned on or after July 15, 2025 are valid for five years (earlier ones remain lifetime) — confirm current details on Cisco’s page. See CCST Networking (100-150) →

Frequently asked questions

Is the 100-160 exam entry-level?
Yes. CCST Cybersecurity is one of Cisco’s entry-level certifications, with no prerequisites, designed for students, interns, and entry-level IT and cybersecurity staff.
How long is the exam and how is it scored?
The exam runs 50 minutes and is reported as pass/fail. Cisco does not publish a public numeric cut score, and the number of questions can vary by exam form. Confirm current details on Cisco’s exam page.
What comes after CCST Cybersecurity?
Unlike the other CCST exams (whose step-up is CCNA), the stated next step from CCST Cybersecurity is Cisco’s CyberOps Associate (200-201), which goes deeper into security operations. You can also broaden your foundation with CCST IT Support or CCST Networking.
How long is CCST Cybersecurity valid?
Cisco states that CCST certifications earned on or after July 15, 2025 are valid for five years, while those earned before that date remain lifetime credentials. Confirm current renewal terms with Cisco.
Does Cisco publish domain weights for 100-160?
Cisco publishes the five objective areas but not a fixed percentage weight for each. Prepare across all five; incident handling and endpoint security map closely to real support work, so give them practical attention while keeping your preparation balanced.

Start your free 24-hour 100-160 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-objective-area across all five CCST Cybersecurity domains. No credit card required.

Start free trial →