Cisco Certified Support Technician (CCST) Networking Study Guide
- Time limit
- 50m
- Passing score
- Pass/Fail
- Exam fee
- $125
- Governing body
- Cisco
The Cisco Certified Support Technician (CCST) Networking certification is an entry-level credential designed to validate foundational networking knowledge for people just starting an IT career. It confirms that a candidate understands how networks are built, addressed, connected, and troubleshot at a basic level, without requiring prior professional certification experience.
- Network Support Technicians
- IT Support Technicians
- Help Desk Technicians
- IT Support Specialists
The certification matters career-wise because it gives newcomers a credible, vendor-recognized way to demonstrate baseline networking competence to employers, often before or alongside a first help-desk or support role. It also functions as a structured on-ramp into the broader Cisco certification ecosystem, giving candidates a concrete goal to study toward instead of trying to absorb networking concepts without direction.
Why It's a Smart Starting Point
Because it sits at the entry level of Cisco's certification track, CCST Networking is intentionally accessible: it assumes no prior certifications and is built for people who are new to networking but want to prove they grasp the fundamentals. For many candidates, it becomes the first item on a resume that eventually leads toward more advanced Cisco credentials.
Understanding the exam's structure and logistics helps candidates plan their study timeline and budget before registering.
Format and Duration
The CCST Networking exam carries the exam code 100-150 and runs for a fixed duration of 50 minutes. Results are reported on a pass/fail basis, and Cisco does not publish a specific numeric cut score that candidates need to hit — instead, the report simply indicates whether the candidate passed.
Cost and Registration
Registering for the exam costs 125 USD. Candidates can alternatively purchase a Cisco Certified Support Technician Exam Voucher for 130 USD, which can then be redeemed to schedule the exam. Each voucher covers a single exam attempt, and because Cisco offers three separate CCST exams, a distinct voucher is needed for each one if a candidate is pursuing more than one.
Delivery and Prerequisites
The exam is delivered exclusively through Certiport, a Pearson VUE business, and a voucher can be redeemed either at a Certiport Authorized Testing Center or through remote proctoring, giving candidates flexibility in how and where they sit for the test. There are no additional prerequisites required to register — anyone can sit for the exam directly. That said, candidates who pass typically arrive with a meaningful base of preparation: Cisco notes that successful candidates generally have at least 150 hours of instruction and hands-on experience behind them before testing.
The exam objectives are organized into 6 domains, spanning 6 main topic areas overall. Cisco's official objective document does not publish a percentage weighting for each individual domain, so candidates should treat all six as roughly equally important rather than trying to over-index on any single area.
Domain 1: Standards and Concepts
Covers the fundamental conceptual building blocks of networks, including the TCP/IP model, the OSI model, frames and packets, and the distinctions between LAN, WAN, MAN, CAN, PAN, and WLAN network types.
Domain 2: Addressing and Subnet Formats
Covers private versus public addresses, IPv4 addresses and subnet formats, and IPv6 addresses and prefix formats — the mechanics of how devices are identified and grouped on a network.
Domain 3: Endpoints and Media Types
Covers cables and connectors, the differences between Wi-Fi, cellular, and wired technologies, and how to set up network connectivity across different operating systems.
Domain 4: Infrastructure
Covers Cisco device status lights, network diagrams and cabling, device ports, and basic routing and switching concepts — the physical and logical layout of a working network.
Domain 5: Diagnosing Problems
Covers troubleshooting methodologies, packet capture with Wireshark, basic diagnostic commands, and basic show commands used on a Cisco network device.
Domain 6: Security
Covers how firewalls filter traffic, foundational security concepts including CIA and AAA, and configuring basic wireless security such as WPA, WPA2, and WPA3.
Because the exam has no formal prerequisites, candidates arrive with widely varying backgrounds. A structured, domain-by-domain approach tends to work better than cramming, especially since the exam window itself is only 50 minutes and leaves little room for uncertainty on test day.
Weeks 1-2: Foundations
Start with Domain 1 (Standards and Concepts) and Domain 2 (Addressing and Subnet Formats). These two domains form the conceptual backbone for everything else — the OSI and TCP/IP models, packet versus frame terminology, and IPv4/IPv6 addressing and subnetting. Practice subnetting by hand until it's fast and automatic.
Weeks 3-4: Physical and Logical Infrastructure
Move into Domain 3 (Endpoints and Media Types) and Domain 4 (Infrastructure). Focus on recognizing cable and connector types, understanding wired versus wireless versus cellular tradeoffs, interpreting Cisco device status lights, and reading basic network diagrams alongside routing and switching fundamentals.
Weeks 5-6: Troubleshooting and Security
Work through Domain 5 (Diagnosing Problems) and Domain 6 (Security). Get comfortable with a troubleshooting methodology, practice reading Wireshark packet captures, memorize a handful of basic show and diagnostic commands, and review firewall behavior, the CIA triad, AAA, and wireless security standards like WPA2 and WPA3.
Final Week: Integration and Review
Spend the last stretch cycling through all six domains using flashcards and practice questions rather than re-reading material passively. Since no domain weighting is published, treat weak spots in any domain as equally worth shoring up, and aim to comfortably recall material from the full 150-hour recommended preparation baseline rather than any single topic.
With only 50 minutes on the clock, pacing matters as much as knowledge. A candidate who lingers too long on a handful of tricky addressing questions can run short of time before reaching later material.
Before the Exam
- Confirm whether you are testing at a Certiport Authorized Testing Center or via remote proctoring, and prepare accordingly — remote proctoring typically requires a clear workspace and stable internet connection.
- Bring valid identification and arrive or log in with enough buffer time to handle check-in procedures without eating into your test window.
- Review your voucher or registration confirmation in advance so there are no surprises about which exam you are scheduled for.
During the Exam
- Skim through subnetting and addressing questions first if you find them time-consuming, and flag anything uncertain to revisit rather than stalling.
- Read each question fully before answering — networking exams often include distractor answers that are correct for a similar but different scenario.
- Since the result is pass/fail rather than a scaled score, focus on answering every question rather than perfecting a handful.
Common Mistakes to Avoid
The most common misstep is treating the six domains unevenly because a candidate assumes some matter more than others — but since Cisco does not publish individual domain weightings, under-preparing any one domain is a real risk. Another frequent mistake is memorizing terminology without hands-on practice; concepts like subnetting, show commands, and packet capture interpretation are best learned by doing, not just reading.
Because CCST Networking spans six distinct domains ranging from conceptual models to hands-on troubleshooting commands, a mix of study formats tends to work better than any single method alone.
Practice Questions
Working through practice questions organized by domain helps surface which of the six domains — standards and concepts, addressing, endpoints and media, infrastructure, diagnosing problems, or security — need more attention before test day. Since Cisco does not publish per-domain weightings, practice questions spread evenly across all six areas give a more reliable signal of readiness than focusing narrowly on a favorite topic.
Flashcards
Flashcards are particularly well suited to the more memorization-heavy corners of this exam: cable and connector types, Cisco device status light meanings, basic show and diagnostic commands, and wireless security standards like WPA, WPA2, and WPA3. Short, repeatable review sessions help this kind of factual recall stick without requiring long study blocks.
Glossary
A glossary of networking terminology is useful for quickly clarifying unfamiliar terms encountered while studying Domain 1's conceptual models or Domain 6's security fundamentals, such as CIA and AAA, without having to break study momentum to search elsewhere.
Used together, these free resources let a candidate build both the conceptual understanding and the practical recall the CCST Networking exam actually tests.
CCST Networking flashcards
30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.
Browse all 30 cards
What is VLAN and why is it used?
A VLAN (Virtual Local Area Network) logically segments a single physical switch into multiple isolated broadcast domains, improving security and reducing unnecessary broadcast traffic.
What is the CCST Networking exam code and how long is the exam?
The exam code is 100-150, and candidates are given 50 minutes to complete it.
Which testing provider delivers the CCST certification exams?
Certiport, a Pearson VUE business, delivers the CCST exams at authorized testing centers or via remote proctoring.
How many domains make up the CCST Networking exam blueprint?
The exam objectives are organized into 6 domains covering standards and concepts, addressing, endpoints and media, infrastructure, diagnosing problems, and security.
What are the seven layers of the OSI model, in order from top to bottom?
Application, Presentation, Session, Transport, Network, Data Link, and Physical.
How many layers does the TCP/IP model have, and what are they?
Four layers: Application, Transport, Internet, and Network Access (sometimes split into Link and Physical), which map onto the seven-layer OSI model.
What is the difference between a frame and a packet?
A frame is a Data Link Layer (Layer 2) protocol data unit that includes MAC addressing, while a packet is a Network Layer (Layer 3) protocol data unit that includes IP addressing.
Define LAN, WAN, and MAN.
A LAN (Local Area Network) covers a small area like an office or building; a WAN (Wide Area Network) spans large geographic distances connecting multiple LANs; a MAN (Metropolitan Area Network) covers a city-sized area, larger than a LAN but smaller than a WAN.
What distinguishes a PAN from a WLAN?
A PAN (Personal Area Network) connects devices within a very short range around a single person, such as via Bluetooth, while a WLAN (Wireless Local Area Network) provides wireless connectivity across a local area, typically via Wi-Fi access points.
What is the range of private IPv4 addresses defined by RFC 1918?
10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 are reserved for private use and are not routable on the public internet.
What is CIDR notation and what does the number after the slash represent?
CIDR (Classless Inter-Domain Routing) notation expresses an IP address with its subnet mask, where the number after the slash indicates how many bits of the address are used for the network portion.
How many bits make up an IPv6 address, and how is it typically written?
An IPv6 address is 128 bits long, written as eight groups of four hexadecimal digits separated by colons, with consecutive zero groups optionally compressed using a double colon.
What is an IPv6 link-local address and what prefix does it use?
A link-local address is used for communication only within a single network segment and is not routable; it uses the fe80::/10 prefix and is automatically assigned to every IPv6-enabled interface.
What is the difference between a subnet mask and a default gateway?
A subnet mask defines which portion of an IP address identifies the network versus the host, while a default gateway is the router address a device sends traffic to when the destination is outside its own subnet.
Name three common twisted-pair cable connector types and their typical use.
RJ-45 connectors terminate Ethernet twisted-pair cabling, while RJ-11 connectors are used for telephone lines; both use modular jack designs but differ in pin count and width.
What is the difference between straight-through and crossover Ethernet cables?
A straight-through cable connects dissimilar devices such as a PC to a switch, while a crossover cable connects similar devices such as switch to switch; modern NICs with Auto-MDIX often make this distinction unnecessary.
What is the difference between single-mode and multimode fiber optic cable?
Single-mode fiber uses a narrow core and laser light to carry a single signal path over long distances, while multimode fiber uses a wider core and LED light suited for shorter-distance, lower-cost connections.
What does the term 'status light' on a Cisco device typically indicate?
LED status lights on Cisco switches and routers indicate port link status, activity, duplex mode, and speed, letting a technician quickly diagnose physical-layer connectivity without a console session.
What is the difference between a switch and a router at a basic level?
A switch forwards frames between devices on the same network based on MAC addresses (Layer 2), while a router forwards packets between different networks based on IP addresses (Layer 3).
What command is commonly used on a Cisco device to display interface status and configuration summary?
The 'show ip interface brief' command displays a summary of interface status, IP addresses, and up/down state on a Cisco IOS device.
What is the purpose of the traceroute command?
Traceroute identifies the path a packet takes across routed hops to a destination, displaying each intermediate router and the round-trip time, useful for isolating where connectivity fails.
What does the ping command test and what protocol does it use?
Ping tests basic reachability between two hosts using ICMP Echo Request and Echo Reply messages, confirming that a target device is responding on the network.
What is Wireshark used for?
Wireshark is a packet capture and protocol analysis tool that lets technicians inspect live or recorded network traffic in detail to diagnose issues at multiple protocol layers.
What is the standard troubleshooting methodology structure commonly taught for networking?
A structured troubleshooting approach typically involves identifying the problem, establishing a theory of probable cause, testing the theory, implementing a solution, and verifying full functionality.
What does the CIA triad stand for in security concepts?
Confidentiality, Integrity, and Availability — the three foundational goals of information security that guide how systems and data are protected.
What does AAA stand for in network security?
Authentication, Authorization, and Accounting — a framework for verifying identity, granting appropriate access, and tracking user activity on a network.
What is the primary function of a firewall?
A firewall filters network traffic based on defined rules such as source/destination address, port, or protocol, permitting or denying packets to protect a network from unauthorized access.
What is the difference between WPA2 and WPA3 wireless security?
WPA3 improves on WPA2 by using stronger encryption and Simultaneous Authentication of Equals (SAE) for the handshake, offering better protection against offline password-guessing attacks than WPA2's pre-shared key exchange.
What is DHCP and what problem does it solve?
DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses, subnet masks, default gateways, and DNS servers to devices on a network, eliminating the need for manual IP configuration.
What is DNS and what is its core function?
DNS (Domain Name System) translates human-readable domain names into IP addresses so that devices can locate and connect to network resources without users needing to remember numeric addresses.
CCST Networking glossary
24 terms the CCST Networking tests, defined in plain English.
- AAA
- Authentication, Authorization, and Accounting — a security framework for controlling and tracking who can access a network and what they are permitted to do.
- CCST
- Cisco Certified Support Technician, an entry-level Cisco certification designed as a first step toward the CCNA and aimed at technicians in help desk and IT support roles.
- CIA Triad
- A foundational security model consisting of Confidentiality, Integrity, and Availability, used to guide the design and evaluation of secure systems.
- CIDR
- Classless Inter-Domain Routing — a method of allocating IP addresses and specifying subnet size using a slash notation (e.g., /24) instead of traditional class-based addressing.
- Default Gateway
- The router interface address a host uses to send traffic destined for any network outside its own local subnet.
- DHCP
- Dynamic Host Configuration Protocol — a service that automatically assigns IP addressing information to devices joining a network.
- DNS
- Domain Name System — a distributed naming service that resolves human-readable domain names into IP addresses.
- Firewall
- A security device or software function that inspects and filters network traffic according to a defined rule set to block unauthorized access.
- IPv4
- Internet Protocol version 4, a 32-bit addressing scheme typically written in dotted-decimal notation (e.g., 192.168.1.1) that remains the dominant addressing method on most networks.
- IPv6
- Internet Protocol version 6, a 128-bit addressing scheme written in hexadecimal notation, designed to replace IPv4 and provide a vastly larger address space.
- LAN
- Local Area Network — a network confined to a small geographic area such as a single building or office.
- MAC Address
- A Media Access Control address is a unique hardware identifier burned into a network interface card, used for Layer 2 frame delivery within a local network.
- NAT
- Network Address Translation — a process that maps private internal IP addresses to a public IP address, allowing multiple devices to share one internet-facing address.
- OSI Model
- A seven-layer conceptual framework (Physical, Data Link, Network, Transport, Session, Presentation, Application) used to describe how data moves through a network.
- Router
- A Layer 3 networking device that forwards packets between different networks based on destination IP addresses.
- Single-Mode Fiber
- A fiber optic cable type with a narrow core that carries a single light path, typically using laser sources for long-distance, high-bandwidth connections.
- Subnet Mask
- A 32-bit value paired with an IPv4 address that identifies which portion of the address represents the network and which represents the host.
- Switch
- A Layer 2 networking device that forwards frames between connected devices on the same network based on learned MAC addresses.
- TCP/IP Model
- A four-layer networking model (Network Access, Internet, Transport, Application) that underlies real-world internet communication and maps to the OSI model's layers.
- Traceroute
- A diagnostic utility that maps the sequence of routed hops a packet travels to reach a destination, helping isolate where a connectivity failure occurs.
- VLAN
- Virtual Local Area Network — a logical grouping of switch ports that creates isolated broadcast domains on shared physical switching hardware.
- WAN
- Wide Area Network — a network that spans a large geographic area, typically connecting multiple LANs across cities or countries.
- Wireshark
- An open-source packet capture and protocol analysis application used to inspect network traffic in detail for troubleshooting and security analysis.
- WPA3
- Wi-Fi Protected Access 3 — the current generation of wireless security protocol, offering stronger encryption and handshake protection than its predecessor, WPA2.
Sources
- 1.CCST Networking Objective Domains (Exam 100-150) — Cisco (accessed Jul 18, 2026)
- 2.CCST Networking Exam Overview — Cisco (accessed Jul 18, 2026)
- 3.Cisco Certified Support Technician — Overview — Certiport (Pearson VUE) (accessed Jul 18, 2026)
- 4.Cisco Certified Support Technician Exam Voucher — Certiport Store — Certiport (Pearson VUE) (accessed Jul 18, 2026)
- 5.Getting to Know the CCST Networking Certification Exam (Certiport Blog) — Certiport (Pearson VUE) (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- CCST Networking Objective Domains (Exam 100-150)Ciscolearningcontent.cisco.com
- CCST Networking Exam OverviewCiscocisco.com
- Cisco Certified Support Technician Exam Voucher — Certiport StoreCertiport (Pearson VUE)store.certiport.com
- Cisco Certified Support Technician — OverviewCertiport (Pearson VUE)certiport.pearsonvue.com
- Getting to Know the CCST Networking Certification Exam (Certiport Blog)Certiport (Pearson VUE)certiport.pearsonvue.com
- Cisco Certified Support Technician Exam VoucherCertiportstore.certiport.com
Last verified against the official exam content outline: