
Marius welcomes you and outlines the Cisco cyber security operations fundamentals exam 200 201, highlighting hands-on labs, lectures, and the topics covered.
Prepare for the CCNA Cybersecurity 200-201 exam with a clear focus on the OSI model, TCP/UDP/ARP concepts, and AI updates, presented as accessible, high-level fundamentals with real-world labs.
Explore the topology with a wide area network and local network, web servers and laptops, protected by three firewalls—Cisco Firepower, Zyxel USG, and pfSense open source.
Explore Cisco Firepower 1010 as an all-in-one firewall, connect a LAN, and begin setup from scratch while comparing pfSense and Zyxel for VPNs and DDoS protection in small office environments.
Learn Cisco firepower setup: connect internet and LAN with two cables, access 192168.95.1, and leverage a 90-day trial of threat, malware, URL filtering, and intrusion prevention.
Apply the CIA triad—confidentiality, integrity, and availability—through real-world examples like BitLocker and VPNs, and learn how hashing and high availability prevent a single point of failure.
Master basic Cisco commands by connecting with a console cable using CLI tools like SecureCRT or Putty, then enter user mode, enable, configure globally, with show ip interface brief.
Harden the system by closing telnet ports and using SSH; apply defense in depth with edge firewall and a dedicated monitoring system, following the least privilege.
Learn how hashes protect Cisco images and verify file integrity for iOS updates, using MD5 and SHA-512, and confirm results with app-based or Cisco verify commands.
Explore network security, endpoint security, and application security, and see how firewalls, IDS/IPS, VPN, DLP, and web application firewalls protect web servers from threats like SQL injection.
Compare agent-based and agentless protection for endpoints and networks, explore hybrid defense in depth with firewalls, IPS, VPN, and SNMP, and trace malware protection from signatures to AI-driven zero-day defense.
Explore syslog as a method to forward network logs to a dedicated server, configure log levels 0–7, enable logging, and verify new messages for a robust logging strategy.
Explore two security tools for logs: a centralized system that collects, analyzes, and correlates events from multiple devices. Automate responses and strengthen threat detection with modules and threat intelligence.
Explore cloud service models from on-prem to SaaS, IaaS, and PaaS, and learn how virtualization with virtual machines, hypervisors like VirtualBox, and private key encryption power modern cloud solutions.
Explore malware analysis with any.run sandbox to observe how suspicious files behave in windows and linux, using controlled environments; analyze process details, indicators, and behavior graphs to understand malicious activity.
Explore core security concepts, including threats, risk, vulnerability, attack surface, and encryption, with real-world examples of social engineering and data loss prevention.
Protect your network by understanding threats, threat hunting workflows (plan, execute, report), and real-time attack maps from Fortinet and Bitdefender, with file analysis and log monitoring to detect insider risks.
Perform static and dynamic analysis of files using tools like VirusTotal and sandboxed execution to reveal behavior, memory activity, IP connections, and potential malware for automated reporting.
Explore runbook automation for cyber security, using scripted workflows to detect incidents, assess severity, respond, and escalate, automating tasks such as scans, reporting, and blocking a PC.
Identify, assess, and prioritize risks to assets using a risk matrix to guide decisions on avoidance, transfer, or mitigation. Communicate the results clearly to senior managers who are non-technical.
Explore risk mitigation across technical, administrative, and physical controls with examples like firewalls, encryption, and NDAs; assess PII risk under GDPR and emphasize change management and provenance.
Compare duck owner based permissions with a high-security approach using security labels, then examine role-based access control (RBAC) and attribute-based access control (ABAC) to distinguish their use and flexibility.
In this lab, learn to configure a Cisco firepower access control list to block ICMP from the LAN to the internet, creating a host-based rule, deploying, and verifying hits.
Identify network vulnerabilities through threat intelligence by submitting and consulting CVEs in a centralized database, and leverage services like Cisco Umbrella for DNS security and protection.
Explore how CVE identifiers map to CVSS scores, explain base metrics like attack vector, complexity, privileges, and impact on confidentiality, integrity, and availability, with Cisco Identity Services Engine examples.
Explore data visibility challenges and how to monitor network activity with Cisco Firepower, including SSL inspection, host visibility, and isolating BYOD and IoT devices from web servers.
Block an app using Cisco Firepower by creating and deploying an access rule from inside to outside, exemplified by blocking TeamViewer and reviewing rule priority and deployment.
Identify data loss risks from traffic profiles by spotting unusual volumes and patterns, even with encrypted payloads. Baseline normal activity by user, system, and time to detect profile changes.
Compare rule-based detection with signatures and hashes to behavioral and stat-based anomaly detection. Build layered defenses, establish baselines, and monitor for unusual data patterns and zero-day threats.
Install Wireshark and open it to view your network interface cards; capture traffic by selecting the active interface and filtering for icmp to observe ping messages.
Explore the five tuple—source and destination IPs, ports, and protocol—by capturing traffic with Wireshark in a hands-on lab. Learn to use log correlation to identify patterns and threats.
Follow a tcp stream in Wireshark to reveal a telnet session and arp or dhcp traffic, using filters to focus on ip addresses and protocols.
Master tcpdump on Linux to analyze all network traffic, compare it with Wireshark's interface, and save captures for later opening in Wireshark.
Explore how NetFlow and next-generation firewalls provide visibility into network traffic, leveraging Cisco's NetFlow, IPFIX, deep packet inspection, user identity, and application control.
Explore web content filtering by restricting categories and sites with Cisco's categories and groups, using white lists and black lists to control access and apply exceptions.
Configure a url filtering policy on Cisco Firepower to block or allow sites by category, using whitelist and blacklist, verify categories, and apply access control with real-world examples.
Network visibility underpins detection, revealing data from network and hosts to prevent unseen threats. Deploy SSL inspection to see encrypted traffic, and manage host visibility and scalable data collection.
Cisco firepower enables ssl inspection by acting as a trusted man-in-the-middle to decrypt tls traffic and allow inspection of https content.
Learn standard, extended, and named ACLs on Cisco devices, filtering by source IP, destination, protocol, and port, and apply with ip access-group on interfaces and vty lines.
Explore how network address translation and port address translation hide private IPs behind a public IP, enabling logs, monitoring, and identity verification of who accessed protected resources.
Explore tunneling challenges in modern networks, focusing on SSL inspection and deep packet inspection to reveal encrypted traffic, while noting privacy tools like Thor and risks of hidden paths.
Learn encryption concepts, including symmetric and asymmetric keys, password-protected zip files with AES, and why organizations block encrypted archives, plus how encryption tests protect networks with advanced cybersecurity solutions.
Demonstrates a brute force attack on a Cisco device password using Medusa in Kali Linux, testing SSH on port 22 with a dictionary file and admin credentials.
Explore peer-to-peer networks, encapsulation, and load balancing, examining data visibility trade-offs, potential vulnerabilities, and the importance of monitoring logs and timely incident response.
Explore pf sense web proxy and web proxy filter modules, focusing on caching to speed browsing, URL filtering to block access, and managing access lists and blacklist domains.
Explore data types in security monitoring, from full packet capture with headers and payloads to session data and NetFlow. Learn how transaction data, metadata, and alerts guide investigations.
Learn how TCP, UDP, HTTP, ARP, ICMP, DHCP, and DNS enable threats like three-way handshake abuse, MITM, spoofing, and floods that cause DDoS and DoS.
Use nmap to scan networks and identify open ports, discovering devices and http or https access. Compare with angry ip scanner on Windows, noting antivirus flags and safe test guidance.
Explore network and web attacks, including protocol-based threats, ddos, and man-in-the-middle techniques. Learn defenses such as input sanitization to prevent sql injection, command injection, and cross-site scripting.
Explore the DoS denial of service attack using nmap to verify open ports, tcp syn flood, and icmp flood with hping3, and firewall detection.
Demonstrates a man-in-the-middle attack via ARP spoofing to redirect traffic through the attacker. Uses Kali Linux and Arpspoof to spoof the default gateway, with Wireshark evidence.
Study web application attacks in a hands-on lab, identifying SQL injection, command injection, and cross-site scripting, and observe their detection and blocking by firewalls with logs and alerts.
Improve cybersecurity visibility across network, host, and cloud to enable detection. Learn how encrypted traffic, data scale, and cloud limits demand multi-layer visibility and SSL inspection.
Explore social engineering and phishing tactics that trick users into clicking links and revealing access to a fake online bank. Learn how attackers exploit willingness to help and recent purchases.
Guard endpoints from buffer overflow and malware threats such as rootkits, ransomware, viruses, and trojans, and deter command-and-control and DDoS activity through input validation and enterprise antivirus with updates.
Explore zero trust networking, where access is denied by default and explicit permissions govern services and documents. Examine evasion techniques like tunneling, encryption, proxying, and Tor.
Learn how certificates authenticate identities through a trusted certificate authority, why self-signed certs trigger browser warnings, and how to configure trust to ensure encrypted connections remain private.
Identify digital certificates via the x.509 standard, distinguish encryption from key exchange with diffie-hellman and tls 1.3, and emphasize aes and sha-256/512 while avoiding md5 and 3des.
Explore endpoint technologies with host-based intrusion detection and prevention on end devices, real-time monitoring, and cloud-based antivirus requiring internet access and AI-driven analysis.
Configure Windows Defender firewall with advanced security to manage inbound and outbound rules, allowing remote tools like VNC while blocking ICMP on public networks with a basic, stateful packet-filtering approach.
Master Windows 11 and Linux security basics, interpret Event Viewer logs and warnings, and explore Kali Linux with tcpdump and hands-on attacks like denial of service and man-in-the-middle.
Test networks with Speedtest.net for latency, download, and upload, then use iperf in client-server mode on Windows and other platforms to measure LAN and wireless performance, including UDP and ports.
Demonstrates a mac flood attack on a local area network using kali linux to overwhelm a switch with mac addresses, turning it into a hub and enabling possible man-in-the-middle attacks.
Prepare for the Cisco Cybersecurity Operations Fundamentals v1.2 (200-201) exam and build the real-world skills required to work in a modern SOC (Security Operations Center). This comprehensive course covers all core exam topics, blending theory with hands-on labs so you gain practical, job-ready experience.
What You’ll Learn:
Security Concepts – CIA triad, defense-in-depth, access control models, risk/threat/vulnerability analysis, threat intelligence, malware analysis.
Security Monitoring – traffic capture & analysis (TCPdump, Firewalls, AV, Syslog), data visibility challenges, identifying DoS, DDoS, MitM, and L7 application-layer attacks.
Host-Based Analysis – intrusion detection, endpoint security, malware forensics, evidence collection, log interpretation.
Network Intrusion Analysis – working with Wireshark, IDS/IPS, deep packet inspection, file extraction, intrusion event analysis.
Security Policies & Procedures – incident response with NIST SP800-61, SOC metrics, server/network profiling, handling sensitive data.
Extensive Hands-On Labs:
Unlike many theory-only trainings, this course is lab-intensive. You’ll get guided practice on:
Cisco Firepower NGFW – IPS, intrusion prevention, application visibility, web filtering.
pfSense – firewalling, VPNs, advanced filtering, IDS/IPS.
Zyxel appliances – gateway security, threat filtering.
Cisco Catalyst 3560CX – switch security, ACLs, port security, monitoring.
Kali Linux – offensive security tools for DoS, Man-in-the-Middle, web application attacks, and traffic analysis.
AI - a demo of building a dashboard monitoring a Cisco switch (python + ChatGPT)
Through these labs, you will simulate real-world attack and defense scenarios, including:
Network attacks
Man-in-the-Middle interception
Layer 7 (application) attacks
IPS tuning and response
Web content filtering and policy enforcement
Why This Course?
Covers the Cisco 200-201 exam blueprint
Offers hands-on approach
E-book with all the notes (160+ pages)
Builds real SOC analyst skills with practical, tool-based labs
Ideal for beginners aiming for CCNA CyberOps or IT professionals transitioning into cybersecurity
Join now!