๐ŸŽ„

CertoMetrics - 15% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

Cisco Certified Support Technician (CCST) Cybersecurity (100-160)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

Cisco

Certification

Support Technician

Content

84 Qs

Status

Verified

Updated

5 days ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$108 $69

Save $39 Instantly

  • โœ“
    Full PDF + Interactive Engine Everything you need to pass
  • โœ“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • โœ“
    Priority 24/7 Expert Support Direct line to certification leads
  • โœ“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$59

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$49

Digital Access

  • โœ“ Exam Questions (PDF)
  • โœ“ Mobile Friendly
  • โœ“ 60 Days Updates
Download Free Sample PDF

Verified 17-Question Preview (100-160)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified Cisco certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated 100-160 prep kit.

Exam Overview

The Cisco Certified Support Technician (CCST) Cybersecurity certification is a pivotal entry point for individuals aspiring to launch a career in the dynamic field of cybersecurity. This foundational certification validates your core understanding of cybersecurity principles, common threats, vulnerabilities, and the essential skills required to safeguard digital assets. Earning the CCST Cybersecurity credential demonstrates to employers that you possess a critical baseline knowledge in securing networks, hosts, and data, making you a valuable asset in any IT support or security team. It's an excellent stepping stone, providing a solid foundation for further specialization and advanced Cisco certifications, ultimately boosting your professional credibility and opening doors to exciting career opportunities in cybersecurity.

Questions

45-55

Passing Score

700/1000

Duration

50 Minutes

Difficulty

Beginner

Level

Foundational

Skills Measured

Security Principles and Concepts: Understanding the core tenets of cybersecurity, including confidentiality, integrity, availability (CIA triad), risk management, threat intelligence, and the security lifecycle.
Network Security Fundamentals: Knowledge of network topologies, common network protocols, basic security devices like firewalls and intrusion detection/prevention systems (IDS/IPS), and secure network access.
Host-Based Security: Concepts related to securing endpoints, operating systems, applications, and data, including malware types, antivirus protection, and basic system hardening techniques.
Vulnerability Management and Incident Response: Awareness of common vulnerabilities, methods for vulnerability assessment, and the basic steps involved in identifying, responding to, and recovering from security incidents.
Access Control, Cryptography, and Secure Practices: Understanding authentication, authorization, accounting (AAA), basic cryptographic principles (encryption, hashing), and secure coding practices for end-users.

Career Path

Target Roles

Cybersecurity Technician EntryLevel Security Analyst IT Support Specialist

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest Cisco standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the 100-160 exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated 100-160 bank (17 Questions).

QUESTION 1

Move each cybersecurity term from the list on the left to the correct description on the right.

Note: You will receive partial credit for each correct answer.

 

Technical Scenario Diagram
Answer Canvas

This question tests knowledge of fundamental cybersecurity concepts as defined by standards bodies like NIST. The correct pairings are based on these industry-standard definitions.

Correct Mappings:

โœ… Asset matches with -> People, property, or data
Reasoning: An asset is anything that has value to an organization. This includes tangible items like property and equipment, and intangible items like data, reputation, and personnel.

โœ… Threat matches with -> An action that causes a negative impact
Reasoning: A threat is any circumstance or event with the potential to adversely impact organizational operations or assets. It represents the potential negative action against an asset.

โœ… Risk matches with -> The potential for loss, damage, or destruction
Reasoning: Risk is a measure of the potential for loss resulting from a threat exploiting a vulnerability. It combines the probability of the event and its negative impact.

โœ… Vulnerability matches with -> A weakness that potentially exposes organizations to cyber attacks
Reasoning: A vulnerability is a weakness in a system, process, or control that can be exploited by a threat actor to cause harm.

 



Reference: https://csrc.nist.gov/glossary

QUESTION 2

Move each framework from the list on the left to the correct purpose on the right.

Note: You will receive partial credit for each correct answer.

 

Technical Scenario Diagram
Answer Canvas

This question requires matching well-known cybersecurity and privacy frameworks to their specific purposes. Each framework is designed to protect a particular type of data or applies to a specific industry or region. The solution correctly aligns each acronym with its definition.

โœ… GDPR matches with -> Protects the personal information of members of the European Union
Reasoning: The General Data Protection Regulation (GDPR) is a comprehensive data privacy law from the European Union. It regulates how companies worldwide can collect, use, and store the personal data of EU citizens.

โœ… HIPAA matches with -> Protects the healthcare information of individuals
Reasoning: The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law. Its primary purpose is to set national standards for protecting sensitive patient health information (PHI) from being disclosed without consent.

โœ… PCI-DSS matches with -> Protects the credit card information of individuals
Reasoning: The Payment Card Industry Data Security Standard (PCI-DSS) is a global information security standard. It applies to any organization that accepts, processes, stores, or transmits cardholder data.

โœ… FERPA matches with -> Protects the educational records of individuals
Reasoning: The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records. It gives parents and eligible students rights over those records.

โœ… FISMA matches with -> Protects information about individuals that is stored by federal agencies
Reasoning: The Federal Information Security Modernization Act (FISMA) is a U.S. federal law requiring federal agencies to implement robust security programs for their information systems, including those storing personal data.



Reference: https://www.cisco.com/c/en/us/products/security/what-is-cybersecurity.html#~cybersecurity-frameworks-and-compliance-regulations

QUESTION 3

A corporation hires a group of experienced cyber criminals to create a prolonged and in-depth presence on the network of a competitor. This presence will allow the corporation to steal or sabotage sensitive data from their competitor.

Which type of attack does this scenario describe?

A
DDoS
B
Ransomware
C
Man-in-the-middle
D
APT

Correct Option: D

✅ Option D (Correct)

An Advanced Persistent Threat (APT) involves a prolonged, covert, and sophisticated cyberattack where an unauthorized user gains access to a network and remains undetected for an extended period. The goal is typically data exfiltration, espionage, or sabotage, perfectly aligning with the scenario's description of a competitor establishing a "prolonged and in-depth presence" to "steal or sabotage sensitive data."

❌ Why the other choices are incorrect:

  • Option A is incorrect: DDoS (Distributed Denial of Service) attacks aim to disrupt service by overwhelming a system with traffic, not to maintain a prolonged presence for data theft or sabotage.
  • Option B is incorrect: Ransomware encrypts data and demands payment for its release, which is not the primary objective described in the scenario.
  • Option C is incorrect: Man-in-the-middle attacks involve intercepting communication between two parties. While data can be stolen, it doesn't encompass the broad "prolonged and in-depth presence" for varied sabotage or theft described.


Reference: https://www.cisco.com/c/en/us/products/security/advanced-persistent-threats-apt.html
QUESTION 4

Which three authentication factors are valid for use in a multifactor authentication scenario? (Choose three.)

A
Something you have
B
Something you are
C
Something you know
D
Something you do
E
Something you earn
F
Something you see

Correct Option: A,B,C

Multifactor authentication (MFA) relies on combining two or more distinct types of authentication factors to verify a user's identity. The three primary and universally recognized categories of authentication factors are:

  • A: Something you have: Refers to a physical object, such as a smart card, security token, or a mobile device receiving a one-time password.
  • B: Something you are: Pertains to inherent physical characteristics, also known as biometrics, like a fingerprint, facial scan, or iris recognition.
  • C: Something you know: Involves secret knowledge, typically a password, PIN, or a security question's answer.

Options D, E, and F are not standard, universally accepted authentication factors in cybersecurity frameworks.



Reference: https://www.cisco.com/c/en/us/products/security/what-is-multifactor-authentication-mfa.html
QUESTION 5

What does hashing provide for data communication?

A
Data non-repudiation
B
Origin authentication
C
Data encryption
D
Data integrity

Correct Option: D

โœ… Option D (Correct) Reasoning: Hashing produces a unique, fixed-size value (hash) from data. If the data is altered in any way, the resulting hash will change significantly. This allows recipients to detect if data has been modified during transit or storage, directly ensuring data integrity. โŒ Why the other choices are incorrect: * Option A is incorrect: Hashing is a component in digital signatures, which provide non-repudiation, but hashing alone does not offer this. * Option B is incorrect: Origin authentication often utilizes hashing within digital signatures or MACs but requires cryptographic keys, not just hashing. * Option C is incorrect: Hashing is a one-way function for data verification, not a method for encrypting or concealing data content.



Reference: https://www.cisco.com/c/en/us/products/security/what-is-hashing.html
QUESTION 6

The employees in the accounting department of a company receive an email about the latest federal accounting regulations. The email contains a hyperlink to register for a webinar that provides the latest updates on financial transaction security. The webinar is hosted by a government agency. As a security officer, you notice that the hyperlink points to an unknown party.

Which type of cybersecurity threat should you investigate?

A
Spear phishing
B
Ransomware
C
Smishing
D
Vishing

Correct Option: A

โœ… Option A (Spear phishing) (Correct)

Reasoning: Spear phishing targets specific individuals or departments, leveraging personalized information or relevant topics to appear legitimate. The email to the accounting department, discussing federal regulations and financial security, with a hyperlink to an 'unknown party,' precisely matches this highly targeted and deceptive attack method aimed at exploiting trust to gain access or information.

โŒ Why the other choices are incorrect:

  • Option B is incorrect: Ransomware is a malicious payload that encrypts data, demanding ransom. While it could be the result of a spear phishing attack, the initial threat of the suspicious email and hyperlink is the phishing attempt itself, not the ransomware payload.
  • Option C is incorrect: Smishing involves phishing attacks conducted via SMS text messages. The scenario explicitly states the threat originated from an 'email,' making smishing an incorrect classification for this specific incident.
  • Option D is incorrect: Vishing refers to phishing attacks delivered through voice calls. As the threat vector described is an 'email' containing a hyperlink, vishing is not applicable to this scenario.


Reference: https://www.cisco.com/c/en/us/products/security/what-is-phishing.html#~how-phishing-works
QUESTION 7

For each statement, select True if the statement adheres to the cybersecurity code of ethics or False if it does not.

Note: You will receive partial credit for each correct selection.

 

Technical Scenario Diagram
Answer Canvas

This question assesses understanding of the core ethical principles in cybersecurity. The correct selections align with industry-standard codes of conduct regarding authorization, privacy, and confidentiality. Each statement must be evaluated against these principles.

โœ… A security analyst may use a disgruntled employee's network credentials to monitor behavior. -> False

Reasoning: Using another person's credentials, regardless of the reason, is unethical and likely illegal. It violates privacy, accountability, and non-repudiation principles. Proper monitoring must be conducted through authorized, transparent security tools and processes, not by impersonating a user, which compromises investigations and trust.

โœ… A security analyst may access employee data on a company server if authorized. -> True

Reasoning: Authorization is the key ethical determinant. Security analysts often require access to sensitive data to perform their duties, such as incident response or security audits. This action is ethical and professionally acceptable as long as it is explicitly authorized by company policy and is within the defined scope of their job.

โœ… A security analyst may share sensitive data with unauthorized users. -> False

Reasoning: This is a direct violation of the principle of confidentiality, a fundamental tenet of cybersecurity ethics. A security professional's primary duty is to protect data. Disclosing sensitive information to individuals without a legitimate need-to-know and proper authorization constitutes a severe ethical and professional breach.



Reference: https://www.isc2.org/ethics

QUESTION 8

In order to do online banking, you enter a strong password and then enter the 5-digit code sent to you on your smartphone.

Which type of authentication does this situation describe?

A
Multifactor
B
VPN
C
RADIUS
D
AAA

Correct Option: A

The described scenario is a classic example of multifactor authentication (MFA). MFA requires a user to present two or more distinct authentication factors from different categories to verify their identity. In this instance, the strong password represents 'something you know,' and the 5-digit code sent to the smartphone represents 'something you have.' Both factors must be provided for successful authentication.

VPN refers to a secure network connection, not an authentication type. RADIUS is an authentication protocol. AAA is a framework (Authentication, Authorization, Accounting) for managing user access, not a specific method of combining authentication factors.



Reference: https://www.cisco.com/c/en/us/products/security/what-is-multifactor-authentication-mfa.html
QUESTION 9

Which activity by an adversary is an example of an exploit that is attempting to gain user credentials?

A
Obtaining a directory listing of files located on the web database server
B
Installing a backdoor in order to enable two-way communication with the device
C
Executing a remote port scan of all of the enterprise-registered IP addresses
D
Sending an email with a link to a fictitious web portal login page

Correct Option: D

โœ… Option D (Correct)
Reasoning: Sending an email with a link to a fictitious web portal login page describes a phishing attack. Phishing is a social engineering exploit specifically designed to trick users into voluntarily entering their credentials on a fake site, allowing the adversary to gain them.

โŒ Why the other choices are incorrect:

  • Option A is incorrect: Obtaining a directory listing is an information gathering or reconnaissance activity, not a direct attempt to gain user credentials.
  • Option B is incorrect: Installing a backdoor is a post-exploitation activity for maintaining access and control, not primarily for initial credential acquisition.
  • Option C is incorrect: Executing a remote port scan is a reconnaissance phase activity to identify open services, preceding any attempt to gain credentials.



Reference: https://www.cisco.com/c/en/us/products/security/what-is-cybersecurity.html
QUESTION 10

Move each definition from the list on the left to the correct CIA Triad term on the right.

Note: You will receive partial credit for each correct answer.

 

Technical Scenario Diagram
Answer Canvas

This question tests knowledge of the fundamental cybersecurity model, the CIA Triad. Each definition must be matched to its corresponding principle. The mappings are based on the standard industry definitions of these terms.

The Correct Mappings:

โœ… Confidentiality matches with -> Data should be accessed and read only by authorized users.
Reasoning: Confidentiality is the principle of preventing unauthorized disclosure of information. It ensures that data is accessible only to those who are authorized, aligning perfectly with this definition.

โœ… Integrity matches with -> Data should never be altered or compromised.
Reasoning: Integrity ensures that data is accurate, consistent, and trustworthy over its entire lifecycle. This definition directly reflects the core goal of preventing unauthorized modification or corruption of data.

โœ… Availability matches with -> Legitimate requests should have access to data at all times.
Reasoning: Availability ensures that systems and data are operational and accessible to authorized users when needed. This definition describes the core function of availability in the CIA triad.

 



Reference: https://www.cisco.com/c/en/us/products/security/what-is-the-cia-triad.html

QUESTION 11

Which wireless encryption technology requires AES to secure home wireless networks?

A
WPA
B
TKIP
C
WPA2
D
WEP

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 12

You need to filter the websites that are available to employees on the company network.

Which type of device should you deploy?

A
IPS
B
Proxy server
C
IDS
D
Honeypot

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 13

Which two private IPv4 addresses would be blocked on the Internet to prevent security and performance issues? (Choose two.)

Note: You will receive partial credit for each correct selection.

A
203.0.113.168
B
192.168.18.189
C
224.0.2.172
D
172.18.100.78

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 14

You need to transfer configuration files to a router across an unsecured network.

Which protocol should you use to encrypt the files in transit?

A
TFTP
B
HTTP
C
SSH
D
Telnet

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 15

Several employees complain that the company intranet site is no longer accepting their login information. You attempt to connect by using the URL and notice some misspellings on the site. When you connect by using the IP address, the site functions normally.

What should you do?

A
Restore a backup copy of the authentication database.
B
Verify the accuracy of the entry for the site in the local DNS server.
C
Take the company web portal offline immediately.
D
Update the web server software to the latest version.

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 16

Customers of an online shopping store are complaining that they cannot visit the website. As an IT technician, you restart the website. After 30 minutes, the website crashes again. You suspect that the website has experienced a cyber attack.

Which type of cybersecurity threat should you investigate?

A
Ransomware
B
Social engineering
C
Denial of service
D
Spear phishing

Premium Solution Locked

Unlock all 84 answers & explanations

QUESTION 17

A system on your network is experiencing slower than usual response times. In order to gather information about the status of the system, you issue the netstat -1 command to display all of the TCP ports that are in the Listening state.

What does the Listening state indicate about these ports?

A
The state of the connection on the ports is unknown.
B
The remote end disconnected and the ports are closing.
C
The ports are open on the system and are waiting for connections.
D
The ports are actively connected to another system or process.

Premium Solution Locked

Unlock all 84 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 84 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

> Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

> Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat โ— Active Now

๐Ÿ‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting