


Prepare for the Cisco 200-201 CCNACBR v1.2: Understanding Cisco Cybersecurity Operations Fundamentals exam with focused practice questions aligned with Cisco’s official certification blueprint.
This practice exam course is intended for candidates preparing for the CCNA Cybersecurity certification and professionals who want to test their knowledge of security concepts, security monitoring, host-based analysis, network intrusion analysis, and security policies and procedures.
The course covers essential cybersecurity operations topics including SIEM, SOAR, threat intelligence, threat hunting, malware analysis, endpoint security, NetFlow, packet captures, Wireshark, IDS/IPS, firewalls, PKI, incident response, NIST frameworks, Cyber Kill Chain, Diamond Model, and SOC metrics. Cisco also includes modern topics such as cloud security, containers, DevSecOps, predictive AI, generative AI social engineering, and behavioral detection in the current v1.2 blueprint.
What You'll Learn
Apply security concepts including CIA, risk, vulnerabilities, access control, CVSS, defense in depth, cloud security, threat intelligence, and DevSecOps.
Analyze security monitoring data using SIEM, SOAR, NetFlow, packet captures, firewalls, IDS/IPS, logs, PKI, and network security telemetry.
Investigate host and network threats using Windows and Linux logs, malware reports, IOCs, IOAs, Wireshark, PCAPs, protocol analysis, and detection data.
Apply incident response procedures using NIST guidance, security policies, profiling, evidence handling, Cyber Kill Chain, Diamond Model, and SOC metrics.
Official Cisco 200-201 CCNACBR v1.2 Exam Domains
1. Security Concepts — 20%
This domain covers the foundations of cybersecurity operations.
Topics include:
CIA triad
Network, endpoint, and application security
Agentless and agent-based protection
Antivirus and antimalware
SIEM
SOAR
Log management
Container environments
Virtual environments
Cloud security
Threat intelligence
Threat hunting
Malware analysis
Threat actors
Run Book Automation
Reverse engineering
Sliding-window anomaly detection
Threat modeling
DevSecOps
Risk assessment
Threats
Vulnerabilities
Exploits
Defense in depth
Access control models
Authentication, authorization, and accounting
CVSS
Data visibility
Data-loss indicators
5-tuple analysis
Rule-based detection
Behavioral detection
Statistical detection
Cisco assigns 20% of the current blueprint to Security Concepts.
2. Security Monitoring — 25%
This is the largest domain in the exam.
Topics include:
Attack surface
Vulnerabilities
tcpdump
NetFlow
Next-generation firewalls
Stateful firewalls
Application visibility and control
Web filtering
Email filtering
ACLs
NAT and PAT
Tunneling
TOR
Encryption
Peer-to-peer traffic
Encapsulation
Load balancing
Full packet capture
Session data
Transaction data
Statistical data
Metadata
Alert data
Protocol-based attacks
DoS and DDoS
Man-in-the-middle attacks
SQL injection
Command injection
Cross-site scripting
Generative AI social engineering
Buffer overflows
Command-and-control traffic
Malware
Ransomware
Evasion and obfuscation
PKI
X.509 certificates
Cipher suites
Key exchange
PKCS
Cisco assigns 25% of the exam to Security Monitoring.
3. Host-Based Analysis — 20%
This domain focuses on endpoint security and host-level investigation.
Topics include:
Host-based intrusion detection
Antivirus
Antimalware
Host-based firewalls
Predictive AI
Windows components
Linux components
Attribution
Assets
Threat actors
Indicators of Compromise
Indicators of Attack
Chain of custody
Evidence types
Operating system logs
SIEM logs
SOAR logs
Application logs
Command-line logs
Malware sandbox output
Detonation chamber reports
File hashes
URLs
System events
Network indicators
Cisco assigns 20% of the blueprint to Host-Based Analysis.
4. Network Intrusion Analysis — 20%
This domain focuses on interpreting network-security events and traffic.
Topics include:
IDS/IPS
Firewalls
Application control
Proxy logs
Antivirus events
NetFlow data
False positives
False negatives
True positives
True negatives
Benign activity
Deep packet inspection
Packet filtering
Stateful firewall analysis
Inline traffic inspection
Network taps
Traffic monitoring
Packet captures
Wireshark
TCP stream extraction
Source and destination addresses
Ports
Protocols
Payloads
Ethernet
IPv4
IPv6
TCP
UDP
ICMP
DNS
SMTP
POP3
IMAP
HTTP
HTTPS
HTTP/2
ARP
File and registry artifacts
API calls
Hashes
URLs
Basic regular expressions
Cisco assigns 20% of the exam to Network Intrusion Analysis.
5. Security Policies and Procedures — 15%
This domain focuses on incident response, management controls, evidence, profiling, and SOC operations.
Topics include:
Asset management
Configuration management
Mobile device management
Patch management
Vulnerability management
NIST SP 800-61
Incident response planning
Preparation
Detection and analysis
Containment
Eradication
Recovery
Post-incident analysis
Organization stakeholders
NIST SP 800-86
Evidence collection
Data integrity
Data preservation
Volatile data collection
Network profiling
Server profiling
PII
PSI
PHI
Intellectual property
Cyber Kill Chain
Diamond Model of Intrusion
SOC metrics
Time to detect
Time to contain
Time to respond
Time to control
Cisco assigns 15% of the exam to Security Policies and Procedures.
Exam Domain Summary
DomainWeightSecurity Concepts20%Security Monitoring25%Host-Based Analysis20%Network Intrusion Analysis20%Security Policies and Procedures15%
Who Should Enroll
This course is for candidates preparing for the Cisco 200-201 CCNACBR v1.2 exam, professionals pursuing the CCNA Cybersecurity certification, SOC analysts, junior cybersecurity analysts, incident response professionals, network security technicians, and IT professionals who want additional practice with SIEM, SOAR, NetFlow, IDS/IPS, packet analysis, endpoint investigation, malware analysis, and incident response.
Cisco positions the related training for learners who want the foundational knowledge required to work as an associate-level cybersecurity analyst in a threat-centric SOC.
Requirements
Basic understanding of networking concepts
Familiarity with TCP/IP is helpful
Basic cybersecurity knowledge is useful
Familiarity with Windows and Linux is beneficial
Basic understanding of firewalls and IDS/IPS is helpful
No previous Cisco certification is required
Previous SOC experience is helpful but not required
About the Cisco 200-201 CCNACBR Exam
Exam: Cisco 200-201 CCNACBR
Full Name: Understanding Cisco Cybersecurity Operations Fundamentals
Version: v1.2
Duration: 120 minutes
Price: US$300 or Cisco Learning Credits
Language: English
Certification: CCNA Cybersecurity
Grading: Pass/fail
Cisco states that the exam validates knowledge and skills in security concepts, security monitoring, host-based analysis, network intrusion analysis, and security policies and procedures.
Practice Exam Coverage
Use these practice exams to reinforce your knowledge of:
CIA triad
Risk and CVSS
Threat intelligence
Threat hunting
SIEM and SOAR
NetFlow
Packet capture
Wireshark
IDS/IPS
Firewalls
PKI
Endpoint security
Windows and Linux analysis
Malware analysis
IOCs and IOAs
Network intrusion analysis
Incident response
NIST SP 800-61
NIST SP 800-86
Cyber Kill Chain
Diamond Model
SOC metrics
The practice questions are intended to help identify areas that require additional review and reinforce the knowledge tested on the Cisco 200-201 CCNACBR v1.2 certification exam.