Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which security measure can prevent unauthorized devices from automatically connecting to a corporate network through unused switch ports?
The CCST Cybersecurity Study Guide explains that port security on switches can be configured to limit the number of MAC addresses allowed on a port, or to restrict it to specific devices.
'Port security can prevent unauthorized access by limiting or specifying the MAC addresses allowed to connect through a given switch port. This mitigates risks from rogue devices connecting to the network.'
(CCST Cybersecurity, Basic Network Security Concepts, Switch Security section, Cisco Networking Academy)
Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?
The CCST Cybersecurity Study Guide states that after confirming a vulnerability is relevant and critical, the next step is to apply available patches or mitigations as soon as possible to reduce the attack surface.
'When a critical vulnerability is identified, remediation steps such as applying patches or configuration changes should be implemented immediately to prevent exploitation.'
(CCST Cybersecurity, Vulnerability Assessment and Risk Management, Vulnerability Remediation section, Cisco Networking Academy)
Which wireless security protocol provides the strongest protection for a home or small business network?
The CCST Cybersecurity Study Guide explains that WPA3 is the most current and secure Wi-Fi Protected Access protocol, offering stronger encryption and better protection against brute-force attacks compared to earlier versions.
'WPA3 improves wireless security by using more robust encryption methods and protections against offline password guessing, making it the recommended protocol for securing modern Wi-Fi networks.'
(CCST Cybersecurity, Basic Network Security Concepts, Wireless Security Protocols section, Cisco Networking Academy)
Which security assessment of IT systems verifies that PII data is available, accurate, confidential, and accessible only by authorized users?
The CCST Cybersecurity study material defines Information Assurance (IA) as the practice of managing information-related risks to ensure data availability, integrity, confidentiality, authentication, and non-repudiation. It specifically applies to sensitive information like PII (Personally Identifiable Information).
'Information assurance involves the protection and validation of data so that it remains accurate, confidential, and available only to authorized users. IA ensures the trustworthiness of information, particularly when handling sensitive or regulated data such as PII.'
(CCST Cybersecurity, Vulnerability Assessment and Risk Management, Information Assurance section, Cisco Networking Academy)
A (Risk framing) is part of risk management planning but does not verify data integrity and confidentiality directly.
B (Cyber Kill Chain) is an attack lifecycle model.
C (Workflow management) is about process efficiency, not data protection.
D is correct: Information Assurance addresses the availability, accuracy, and confidentiality of sensitive data.
Which two passwords follow strong password policy guidelines? (Choose 2.)
The CCST Cybersecurity course defines a strong password as one that:
Is at least 8--12 characters long
Uses a mix of uppercase, lowercase, numbers, and symbols
Avoids dictionary words, personal information, and predictable patterns
'Strong passwords combine length, complexity, and unpredictability, making them resistant to brute force and dictionary attacks.'
(CCST Cybersecurity, Essential Security Principles, Authentication and Access Control section, Cisco Networking Academy)
A is correct: It's long, mixed case, includes numbers and symbols, and is not easily guessable.
B is incorrect: It's based on a date, which is predictable.
C is incorrect: Short and based on a dictionary word.
D is correct: Uses complexity and length with leetspeak for added unpredictability.
You need a software solution that performs the following tasks:
Compiles network data
Logs information from many sources
Provides orchestration in the form of case management
Automates incident response workflows
What product should you use?
The CCST Cybersecurity Study Guide explains that SOAR (Security Orchestration, Automation, and Response) platforms integrate data from multiple tools and sources, support case management, and automate security workflows for faster incident response.
'SOAR solutions provide orchestration, automation, and response capabilities. They collect security data from multiple systems, enable analysts to manage incidents, and automate repetitive tasks in the response process.'
(CCST Cybersecurity, Incident Handling, Security Automation Tools section, Cisco Networking Academy)
A (SIEM) collects and correlates security logs but lacks full orchestration and automated response capabilities.
B is correct: SOAR adds orchestration, case management, and automated incident response.
C (NextGen IPS) focuses on intrusion prevention, not orchestration.
D (Snort) is an open-source intrusion detection/prevention tool, not an orchestration platform.
Exam domains verified against: Official Cisco 100-160 exam guide, last checked September 2026.
Understand vulnerabilities, threats, exploits, and attack vectors, plus the CIA triad and encryption fundamentals. This domain covers the foundational concepts that protect systems from harm, including authentication methods like MFA and how public key infrastructure secures communications.
Learn how TCP/IP protocols can be exploited and how network segmentation protects assets across IPv4, IPv6, and hybrid environments. Study firewalls, VPNs, and access control lists that form the perimeter defence between trusted and untrusted networks.
Secure Windows, macOS, and Linux systems by understanding OS security features, system logs, and patch management. This domain teaches you to identify compliance violations in BYOD environments and use tools like netstat and Event Viewer to verify systems meet security policies.
Identify vulnerabilities through active and passive reconnaissance and manage risk by ranking threats and planning recovery. Apply CVE databases and threat intelligence to make mitigation decisions that balance security costs against business impact and disaster recovery needs.
Sample question from this domain above: Q2
Monitor security events using SIEM tools and respond to incidents following the NIST incident response lifecycle. Learn digital forensics, the Cyber Kill Chain framework, and compliance requirements like GDPR that shape how you report and preserve evidence after an attack.
Sample question from this domain above: Q6
Common questions about the exam itself