CCST+Cybersecurity+Objecitve+Domain Cisco Final wCiscoLogo
CCST+Cybersecurity+Objecitve+Domain Cisco Final wCiscoLogo
CCST+Cybersecurity+Objecitve+Domain Cisco Final wCiscoLogo
Objective Domains
The successful candidate has the foundational knowledge and skills necessary to demonstrate
cybersecurity skills. This test will be an entry point into the Cisco Certified program. The next
certification in the pathway is Cisco’s CyberOps.
This is a certification for entry-level cybersecurity technicians, students, interns, etc. The exam targets
secondary and immediate post-secondary students, including entry-level IT and cybersecurity
professionals. The successful candidates are qualified work-ready cybersecurity technicians with at least
150 hours of instruction and hands-on experience.
5. Incident Handling
5.1. Monitor security events and know when escalation is required
• Role of SIEM and SOAR, monitoring network data to identify security incidents
(packet captures, various log file entries, etc.), identifying suspicious events as they
occur
5.2. Explain digital forensics and attack attribution processes
• Cyber Kill Chain, MITRE ATT&CK Matrix, and Diamond Model; Tactics, Techniques,
and Procedures (TTP); sources of evidence (artifacts); evidence handling
(preserving digital evidence, chain of custody)
5.3. Explain the impact of compliance frameworks on incident handling
• Compliance frameworks (GDPR, HIPAA, PCI-DSS, FERPA, FISMA), reporting and
notification requirements
5.4. Describe the elements of cybersecurity incident response
• Policy, plan, and procedure elements; incident response lifecycle stages (NIST
Special Publication 800-61 sections 2.3, 3.1-3.4)