CCST Cybersecurity Study Hub
Exam Code
100-160
Blueprint Items
23
Articles Live
84
Coverage
87% of blueprint covered
Essential Security Principles
1.1
Define essential security principles
1.2
Explain common threats and vulnerabilities
1.3
Explain access management principles
Basic Network Security Concepts
2.1
Describe TCP/IP protocol vulnerabilities
2.2
Explain how network addresses impact network security
2.3
Describe network infrastructure and technologies
2.4
Set up a secure wireless SoHo network
Endpoint Security Concepts
3.1
Describe operating system security concepts — Windows, macOS, Linux security features; Windows Defender; host-based firewalls; CLI and PowerShell; file and directory permissions; privilege escalation
3.2
Demonstrate familiarity with appropriate endpoint tools that gather security assessment information — Using netstat to gather endpoint security data; using nslookup for DNS security assessment; using tcpdump for packet capture and analysis
3.3
Verify that endpoint systems meet security policies and standards — Hardware inventory; software inventory; program deployment; data backups; regulatory compliance (PCI DSS, HIPAA, GDPR); BYOD device management and encryption
3.4
Implement software and hardware updates — Windows Update and application update processes; device drivers and firmware updates; patch management strategies and best practices
3.5
Interpret system logs — Using Event Viewer to interpret Windows logs; audit logs and system and application logs; syslog and centralized log management; identification of anomalies in log data
3.6
Demonstrate familiarity with malware removal — Scanning systems for malware; reviewing and interpreting scan logs; malware remediation steps and best practices
Vulnerability Assessment and Risk Management
4.1
Explain vulnerability management
4.2
Use threat intelligence techniques to identify potential network vulnerabilities
4.3
Explain risk management
4.4
Explain the importance of disaster recovery and business continuity planning — Natural and human-caused disasters; features of DRP and BCP; backup strategies; disaster recovery controls (detective, preventive, corrective)
Incident Handling
5.1
Monitor security events and know when escalation is required — Role of SIEM and SOAR in security operations; monitoring network data to identify security incidents; packet captures and log file analysis; identifying suspicious events and escalation criteria
Coming soon
5.2
Explain digital forensics and attack attribution processes
5.3
Explain the impact of compliance frameworks on incident handling — GDPR compliance requirements and incident reporting; HIPAA compliance and breach notification; PCI-DSS, FERPA, and FISMA frameworks; reporting and notification requirements
Coming soon
5.4
Describe the elements of cybersecurity incident response — Policy, plan, and procedure elements; NIST SP 800-61 lifecycle stages: preparation, detection and analysis, containment, eradication, recovery, and post-incident activity
Coming soon
Browse All CCST Cybersecurity Articles
Last updated 8 September 2026