Cheat Sheet

Cisco CCST Cybersecurity cheat sheet for 100-160 security principles, network defense, endpoint security, vulnerability risk, detection, and incidents.

Use this cheat sheet for fast CCST Cybersecurity review before a practice block or exam-day recap.

Current exam facts

I verified these Cisco facts on May 24, 2026.

Item Value
Exam 100-160 CCST Cybersecurity
Certification Cisco Certified Support Technician Cybersecurity
Duration 50 minutes
Price 125 USD
Languages listed English, Arabic, Chinese, Spanish, French, Japanese, Portuguese
Positioning Entry cybersecurity support foundation

CCST Cybersecurity proof stack

  1. Asset: what system, user, account, or data is involved?
  2. Risk: confidentiality, integrity, availability, identity, exposure, or compliance?
  3. Evidence: log, alert, endpoint event, network flow, user report, vulnerability finding, or policy?
  4. Control: preventive, detective, corrective, technical, administrative, or physical?
  5. Action: document, contain, remediate, mitigate, escalate, or verify?

Fast distinctions

Pair Difference
Authentication vs authorization prove identity vs grant allowed actions
Threat vs vulnerability possible cause of harm vs weakness
Risk vs impact likelihood plus impact vs harm only
IDS vs IPS detect/alert vs block/prevent
Remediation vs mitigation fix/remove weakness vs reduce risk temporarily
Encryption vs hashing reversible protection with key vs one-way integrity/fingerprint use

Control map

Need Start with
protect account access MFA, least privilege, strong authentication, review privileges
reduce lateral movement segmentation, firewall/ACL rules, least privilege
detect suspicious activity logs, SIEM, IDS, EDR, alert correlation
secure endpoint patching, hardening, endpoint protection, host firewall
protect wireless access approved WPA-family security, guest separation, controlled credentials
handle suspected incident validate, scope, contain, preserve evidence, escalate

Final traps

  • Do not treat an alert as confirmed compromise until evidence is validated.
  • Do not prioritize vulnerabilities by score alone; include exposure and business impact.
  • Do not bypass security controls to solve a user convenience problem.
  • Do not destroy evidence before incident scope and containment are understood.
  • Do not confuse secure network design with endpoint hardening; they complement each other.
Revised on Monday, June 15, 2026