Cisco CCST Cybersecurity 100-160 study plan for security principles, network security, endpoint security, vulnerability risk, detection, and incident handling.
Use this study plan if you want a practical route through CCST Cybersecurity without treating it like a memorization list.
| Week | Focus | Outcome |
|---|---|---|
| 1 | Security principles and network security | Explain CIA, risk, controls, identity, segmentation, firewalls, VPNs, and secure protocols. |
| 2 | Endpoint and secure configuration | Recognize patching, hardening, malware, default credentials, endpoint alerts, and safe admin behavior. |
| 3 | Vulnerability risk and detection | Prioritize findings by exposure and impact; read basic firewall, DNS, SIEM, endpoint, and IDS evidence. |
| 4 | Incident handling and mixed review | Follow response phases, practice containment choices, write useful escalation notes, and review traps. |
| Day | Task |
|---|---|
| 1 | Review the cheat sheet and mark weak terms. |
| 2 | Rebuild the CIA, risk, control, authentication, and authorization distinctions from memory. |
| 3 | Practice network security scenarios: firewall, VPN, wireless, segmentation, and protocols. |
| 4 | Practice endpoint and secure-configuration scenarios. |
| 5 | Practice vulnerability prioritization and CVE/CVSS context. |
| 6 | Practice alert triage, log correlation, and incident sequence questions. |
| 7 | Review sample questions and only revisit missed decision patterns. |
For every scenario, say the risk, the evidence, the control, and the next safe support action. If you cannot name all four, the answer is probably still guesswork.