TestPrepPilot
Cisco Certified Network Associate Cybersecurity — quick facts at a glance: requirements, exam format, fees and timeline
Cisco Certified Network Associate Cybersecurity — verified snapshot

The short version

What is the Cisco Certified Network Associate Cybersecurity and is it worth it?

CCNA Cybersecurity (exam 200-201 CBROPS) is Cisco's associate-level cybersecurity certification for Security Operations Center analysts. It is a single 120-minute, ~95-105 question exam costing US$300, delivered by Pearson VUE, and it earns a credential valid for 3 years.

  • Recognized, recruiter-searchable Cisco associate credential for SOC roles
  • Maps to the NICE Cybersecurity Workforce Framework (Tier-1 analyst tasks)
  • Single exam - no core-plus-concentration combination required
  • Strong foundation toward CCNP Security and CCIE Security
  • Validates hands-on alert, log, and packet-analysis skills, not just theory

What is it?

What exactly is the Cisco Certified Network Associate Cybersecurity?

Cisco's associate-level cybersecurity credential that proves you can monitor, analyze, and respond to threats in a Security Operations Center.

The Cisco Certified Network Associate (CCNA) Cybersecurity is delivered via the 200-201 CBROPS (Understanding Cisco Cybersecurity Operations Fundamentals) exam and is Cisco's associate-level security certification, the direct successor to the former CyberOps Associate. It validates the job-ready skills SOC Tier-1 analysts use daily: security concepts, security monitoring, host-based and network intrusion analysis, and incident-handling procedures. Passing it opens roles such as Security Operations Center (SOC) Analyst, Junior Security Analyst, and Threat Analyst. It sits above the entry-level CCST and below the professional CCNP Security in Cisco's cybersecurity pathway, and it requires no formal prerequisite although CCNA-level networking knowledge is helpful.

About Cisco Systems: Cisco certifications are vendor-specific IT and cybersecurity credentials issued by Cisco Systems and delivered through Pearson VUE. They span four tiers - Entry (CCST), Associate (CCNA / CyberOps), Professional (CCNP), and Expert (CCIE) - and validate hands-on networking and security skills. Passing candidates receive a verifiable digital badge (via Credly) and a certificate; all Cisco certifications are valid for three years. Exams are proctored computer-based tests delivered at Pearson VUE test centers or online via OnVUE (CCST is delivered through Certiport/Pearson VUE).

The path in brief

  1. Confirm no formal prerequisite and review the 200-201 blueprint
  2. Complete Cisco's CBROPS course or an aligned SOC-analyst study plan
  3. Practice reading logs, PCAPs, and security alerts in labs
  4. Schedule the 200-201 exam through Pearson VUE (test center or OnVUE)
  5. Pass the exam and claim your Cisco digital badge
  6. Plan CCNP Security (SCOR + concentration) as the next step

Before you book

Who is eligible to sit the Cisco Certified Network Associate Cybersecurity?

Open to all candidates; anyone may register and sit the 200-201 exam through Pearson VUE.

Prerequisites: No formal prerequisite. Cisco recommends a basic understanding of networking, Windows/Linux, and security fundamentals equivalent to CCNA-level knowledge; 150+ hours of related instruction is suggested but not required.

Who it is for: Aspiring and early-career security operations analysts, SOC Tier-1 analysts, network engineers moving into security, and career changers with basic IT knowledge.

The test itself

What is the format of the Cisco Certified Network Associate Cybersecurity?

The Cisco Certified Network Associate Cybersecurity is administered by Pearson VUE and runs 120 minutes and requires Cisco does not publish a fixed passing score; results are reported on a scaled 300-1000 range and the statistical cut score typically falls around 750-850. You receive a pass/fail result with a section-level breakdown. to pass.

Administered byPearson VUE
QuestionsApproximately 95-105 multiple-choice, multiple-response, drag-and-drop, and scenario-based questions
Time limit120 minutes
Pass markCisco does not publish a fixed passing score; results are reported on a scaled 300-1000 range and the statistical cut score typically falls around 750-850. You receive a pass/fail result with a section-level breakdown.
Exam feeUS$300 (plus applicable tax; regional pricing may differ). Redeemable with Cisco Learning Credits.
FormatProctored, computer-based - Pearson VUE test center or online via OnVUE

Content outline

What topics are on the Cisco Certified Network Associate Cybersecurity?

The Cisco Certified Network Associate Cybersecurity is weighted across 5 domains; the largest are Security Concepts (20%), Security Monitoring (25%), Host-Based Analysis (20%).

Weightings come from the official exam outline. Study time is best allocated in roughly these proportions rather than evenly across domains.

  • Security Concepts 20%

    CIA triad, defense-in-depth, access-control models, CVSS, zero trust, core security terminology.

  • Security Monitoring 25%

    Data types from network/endpoint sources, NetFlow, full packet capture, NGFW/IDS-IPS alerts, and how encryption/tunneling affect visibility.

  • Host-Based Analysis 20%

    Endpoint technologies, Windows/Linux artifacts, log evidence, and interpreting host-based tool output during investigations.

  • Network Intrusion Analysis 20%

    Reading IDS/IPS events, PCAP and protocol headers, mapping intrusion artifacts, extracting IOCs from packet/session data.

  • Security Policies and Procedures 15%

    Incident response per NIST SP 800-61, cyber kill chain and diamond model, SOC metrics, chain-of-custody.

The path

How do you register for the Cisco Certified Network Associate Cybersecurity?

  1. 1

    Create a Cisco & testing account~15 minutes

    Set up a free Cisco profile and a Pearson VUE (or Certiport for CCST) candidate profile to schedule and track exams.

    • Register at the Cisco Certification Tracking System
    • Create a Pearson VUE / Certiport candidate profile
    • Confirm your ID documents meet testing requirements
  2. 2

    Choose your certification & exam1-2 hours planning

    Select the target credential and note the exact exam code (e.g., 100-160, 200-201, 350-701 + a concentration).

    • Review the official exam blueprint and topic weights
    • Decide self-study, Cisco U., or instructor-led training
  3. 3

    Prepare with official trainingVaries (weeks-months)

    Use Cisco Networking Academy, Cisco U. courses, official labs, and practice tests aligned to the blueprint.

    • Complete the aligned Cisco U. / NetAcad course
    • Hands-on labs and practice exams
  4. 4

    Schedule the exam via Pearson VUE~10 minutes

    Book a test-center slot or online OnVUE appointment; pay the exam fee (or redeem Cisco Learning Credits).

    • Pick date, time, and location/time zone
    • Pay fee (CCST $125; Associate $300; SCOR $400; concentration $300)
  5. 5

    Take the proctored exam50-120 minutes

    Arrive with valid government ID; complete the exam at a Pearson VUE center or via online proctoring.

    • Check in and pass security/room scan (online)
    • Complete the timed exam
  6. 6

    Get results & digital badgeWithin 48 hours

    Receive a pass/fail result (usually within 48 hours) and, on passing, a Credly digital badge plus certificate; track status in the Certification Tracking System.

    • View section-level score report
    • Accept Credly badge and share it
Preparing for it: Cisco exams are delivered exclusively through Pearson VUE (and Certiport for CCST). Training is available from Cisco U., Cisco Networking Academy, and authorized Cisco Learning Partners; third-party books and labs are widely used but unofficial.

The fine print

What are the retake and renewal rules for the Cisco Certified Network Associate Cybersecurity?

Proctoring & delivery
Delivered by Pearson VUE: at authorized test centers or online via OnVUE remote proctoring (CCST uses the Certiport/Pearson VUE platform). A government-issued photo ID is required; online tests include a room/environment scan.
Retake policy
If you fail, Cisco requires a waiting period of 5 calendar days before you may retake the same exam. Each attempt requires full payment of the exam fee. Cisco does not cap total attempts, but some exams limit attempts within a 12-month window.
Score reporting
Results are reported as pass/fail and made available online (Cisco Certification Tracking System) typically within 48 hours. A section-level performance breakdown is provided to help target further study; scaled scores use a 300-1000 range (CCNA/CCNP-style exams).
Recertification
All Cisco certifications are valid for 3 years from the date earned. Recertify before expiry by (a) passing a higher-or-equal level qualifying exam, (b) earning Continuing Education (CE) credits through eligible training/activities, or (c) a combination of exam + CE. For associate-level certs 30 CE credits are required; for professional-level 40 CE credits. Certificates can also be extended via the Cisco Continuing Education program.
Refunds & rescheduling
Exam fees are generally non-refundable once scheduled, but Pearson VUE allows rescheduling or cancellation up to 24-48 hours before the appointment without penalty; no-shows forfeit the fee. CCST/Certiport policies may differ by region.

Context

Cisco cybersecurity certifications compared

CredentialLevelFocusExamValidity
CCST Cybersecurity Foundational / EntryEntry-level security concepts & support100-160 (1 exam, ~$125)3 years
CCNA Cybersecurity AssociateSOC analyst: monitoring, intrusion & incident analysis200-201 CBROPS (1 exam, $300)3 years
CCNP Cybersecurity ProfessionalProfessional security core + concentrationSCOR 350-701 ($400) + 1 concentration ($300)3 years

What it pays

How much does this credential pay?

$124,910 median for information security analysts (BLS, May 2024) — but tier-1 SOC starts well below it

The occupation this exam points at is Information Security Analysts, and the headline number for that group is genuinely strong: a median of $124,910 in May 2024, and a projected 29 percent employment increase from 2024 to 2034, which is one of the fastest growth rates BLS publishes for any occupation. Two caveats matter enormously if you are using this page to decide whether to spend $300. First, that median describes the whole occupation, including people with a decade of experience and a CISSP. The job 200-201 qualifies you for is tier-1 SOC analyst — alert triage on a rota, often on nights or weekends — and that seat sits nearer the bottom decile than the median. BLS reports that the lowest 10 percent of information security analysts earned less than $69,660, and that is the realistic band for a first monitoring job, with the network-support figure of $73,340 a useful cross-check for what employers pay someone doing shift work with a single associate-level credential. Second, the credential does not do the pay lifting on its own. What moves a tier-1 analyst to tier-2 within eighteen months is demonstrable artefact work — being the person who can open a PCAP and say what happened — and 200-201 is valuable precisely because it is the only associate exam that tests that directly. No published survey isolates holders of this specific credential: Skillsoft's IT Skills and Salary Report reports averages for Cisco certifications generally, but it does not break out CCNA Cybersecurity separately, so we have not quoted a figure that would really be measuring a different exam.

MeasureFigureSource / note
Median annual wage, information security analysts$124,910BLS Occupational Outlook Handbook, May 2024
Lowest 10 percentless than $69,660BLS OOH Pay tab, May 2024 — the band a first tier-1 SOC role sits in
Highest 10 percentmore than $186,420BLS OOH Pay tab, May 2024 — senior/architect roles, not associate-level
Cross-check: computer network support specialists (median)$73,340BLS OOH, May 2024 — comparable pay for shift-based technical monitoring work

Job growth.29% projected growth 2024-34 for information security analysts (much faster than average)

Source: BLS Occupational Outlook Handbook — Information Security Analysts

Your odds

What are the pass rates?

Cisco publishes no pass rate and no cut score for 200-201

Cisco does not publish pass rates for any exam and does not publish the passing score for 200-201 CCNACBR. Its exam pages state only that "grading is pass/fail and results are available online within 48 hours". The underlying mechanism is a scaled score derived from the live item pool, with the cut point set by standard-setting rather than fixed at a round percentage, which is why it is not published and why it can shift when the pool is refreshed — and the pool has just been refreshed, because v1.2 went live in January 2026 with new AI-related objectives. Anyone quoting a specific percentage pass mark for this exam is repeating folklore. What is documented and worth planning around is the retake rule: fail an associate-level exam and you must wait five calendar days, beginning the day after the failed attempt, before you can sit the same exam number again, and you pay the full $300 a second time. Cisco sells an Exam Safeguard product that covers a retake, but it is tied to CCNA, not to this exam, so check the terms before assuming you are covered. There is also a rule in the other direction that surprises people: once you pass, you must wait a minimum of 180 days before taking the same exam number again, which matters if you were planning to re-sit purely to reset a recertification clock. Practically, the useful proxy for readiness is not a rumoured pass rate but your own performance on timed, mixed-domain practice sets that include artefact interpretation rather than definitions.

Read this before quoting the number.No first-time or cumulative pass rate exists in any Cisco publication for 200-201, and Pearson VUE does not release per-exam statistics either. We have left the pass-rate table empty rather than reprint an unsourced number, and any site quoting "the CCNA Cybersecurity pass rate" should be treated with suspicion.

Source: Cisco Exam, Testing, and Certification Policies (retake, scoring and recertification)

Your schedule

How long should I study for it?

120-160 hours of focused study

Two hundred and one is a single 120-minute exam with no second paper, which sounds forgiving until you notice what it actually asks for. This is a defender's exam built around interpreting evidence: reading a packet capture, correlating a NetFlow record against a firewall log, deciding whether a process tree on a Windows or Linux host is normal. You cannot memorise your way to that. The plan below assumes roughly 120-160 hours spread over ten weeks, with the explicit rule that at least a third of your time is spent in front of real data rather than a book. It also assumes you are studying the v1.2 blueprint, live since January 2026, which added AI-focused objectives — AI-assisted threat monitoring, AI-generated social engineering, security risks specific to AI deployments — that are absent from every CyberOps-branded resource published before 2026. If your material says "CyberOps Associate" on the cover, the core five domains are still valid but you must layer the v1.2 additions on top.

  1. Weeks 1-212-14 hrs/week

    Domain 1 — Security Concepts, and the vocabulary the other four domains assume

    • CIA triad, defence in depth, threat actors and attack surface, then the risk vocabulary Cisco uses precisely: risk, threat, vulnerability, exploit
    • Learn the alert classification matrix cold — true positive, true negative, false positive, false negative — with a worked example of each
    • Access control models (DAC, MAC, RBAC, ABAC) and where each is actually deployed
    • Read the v1.2 AI objectives directly from the Cisco exam-topics PDF and note which sub-topics your book predates
  2. Weeks 3-413-15 hrs/week

    Domain 2 — Security Monitoring, the heaviest-weighted domain on the paper

    • Understand what each data source can and cannot tell you: NetFlow, session data, full packet capture, transaction data, alert data, statistical data
    • Install Wireshark and open real captures from a public malware-traffic archive; practise following a TCP stream and extracting an object
    • Learn why encryption, NAT, tunnelling, TOR and P2P each degrade visibility, and what compensating source you reach for
    • Set up Security Onion or Splunk Free and generate then hunt your own events
  3. Weeks 5-612-14 hrs/week

    Domain 3 — Host-Based Analysis

    • Build one Windows and one Linux VM and deliberately generate the evidence: failed logons, a scheduled task, a process launched from a temp directory
    • Read Windows event logs, Sysmon output, and Linux /var/log entries until the field names are familiar rather than novel
    • Learn endpoint technology roles: host firewall, antimalware, application allow-listing, systems-based sandboxing
    • Practise reading a process tree and saying which parent-child relationship is suspicious and why
  4. Weeks 7-813-15 hrs/week

    Domain 4 — Network Intrusion Analysis

    • Work through capture files and identify the attack from the traffic alone: port scan, brute force, SQL injection attempt, DNS tunnelling, beaconing
    • Read IDS alert output alongside the packets that generated it, so signature text stops being abstract
    • Learn protocol header fields that carry investigative value — TTL, TCP flags, HTTP headers, DNS query type
    • Practise extracting files from a capture and hashing them
  5. Week 912-14 hrs/week

    Domain 5 — Security Policies and Procedures, plus the frameworks

    • NIST SP 800-61 incident response lifecycle as an ordered, questionable list
    • Chain of custody, evidence handling, and the order of volatility
    • Map an attack narrative onto the Cyber Kill Chain and onto the Diamond Model — the exam expects both
    • SOC metrics and the tier-1 to tier-3 escalation model
  6. Week 1012-14 hrs

    Timed mixed drilling and the v1.2 delta

    • Full 120-minute timed practice exams, shuffled across all five domains, at least three of them
    • Go back over every AI-related v1.2 objective — these are the items your older resources did not cover
    • Re-drill only the domains where your timed score sits lowest; ignore the ones already comfortable
    • One light revision day before the exam, then stop

Adjusting the pace

Already working tier-1 in a SOC.Six to seven weeks is realistic. Your daily work covers Domains 2 and 5 by osmosis, but your tooling is probably one vendor deep — spend the saved weeks on Domain 4 packet analysis with raw Wireshark rather than your employer's console, because the exam is vendor-neutral in that domain.

Coming from CompTIA Security+ or CySA+.Eight weeks. CySA+ overlaps substantially on monitoring and IR, but 200-201 goes deeper on raw packet and host artefact interpretation and shallower on governance. Cut Weeks 1 and 9 to half, and put every recovered hour into Weeks 3-8.

Career changer with no operational IT background.Sixteen to eighteen weeks at 8 hrs/week. Add a preliminary month on networking fundamentals first — you cannot analyse traffic you cannot read, and candidates who skip TCP/IP basics stall permanently in Domain 4.

How to study

How do I prepare most effectively?

The failure mode on 200-201 is a candidate who can define every term on the blueprint and still cannot answer a question that shows them evidence. Cisco writes this exam from the analyst's chair: here is what you can see, what do you conclude. Everything below is aimed at closing the gap between knowing a concept and recognising it in output.

Live in Wireshark, not in a chapter about Wireshark

Download real capture files from a public malware-traffic archive and work them without reading the write-up first. Follow the TCP stream, identify the user agent, spot the beacon interval, extract the payload. Then read the analyst's write-up and see what you missed. Twenty captures worked this way will teach you more about Domain 4 than any video course, because the exam shows you evidence and asks for a conclusion, which is precisely the motion you are rehearsing.

Build a data-source decision table

The single most repeated question shape in Domain 2 is "the analyst needs to determine X — which data source?" Make a table with the sources down one side (NetFlow, session data, full packet capture, transaction data, alert data, statistical data) and the questions across the top (who talked to whom, how much data moved, what was in the file, which signature fired, is this volume abnormal). Fill it in yourself. The distinction that decides most items is metadata versus payload.

Do not skip the AI objectives added in v1.2

The version live since January 2026 added objectives on AI-assisted monitoring and threat intelligence, identifying AI-generated social engineering, and the security risks introduced by AI deployments themselves. Every book, video course and question bank branded "CyberOps Associate" predates that. Download the current CCNACBR exam-topics document from Cisco and diff it against your resource's table of contents; the delta is small enough to cover in a weekend and large enough to cost you the exam if you ignore it.

Learn the Kill Chain and the Diamond Model as tools, not trivia

Both appear in Domain 5, and candidates memorise the phase names without ever applying them. Take one real intrusion write-up and map it twice — once onto each model. Doing this three or four times means that when the exam gives you a narrative and asks which phase or which vertex, you are recognising a pattern instead of reciting a list.

Practise under forward-only conditions

Cisco presents questions one at a time and does not allow you to return to an item once you have moved past it. Most practice engines let you flag and review, which trains a habit the real exam will punish. Turn review off. Force yourself to commit to an answer, especially on the long artefact items where the temptation to defer is strongest, and get used to the discomfort before exam day rather than during it.

Keep a "why the distractor was tempting" log

For every practice question you get wrong, write one line explaining what made the wrong option attractive. Over ten weeks this becomes a personalised map of how Cisco builds distractors on this exam — usually a real technique that answers a slightly different question, or a data source that would work if the analyst had one more piece of access. Reviewing that log the night before is worth more than another practice test.

What to buy

Which study resources are worth paying for?

Everything on the market for this exam is still branded CyberOps Associate, because the rename to CCNA Cybersecurity only happened in February 2026 and publishers move slower than Cisco marketing. That is fine for the five core domains and a real gap on the v1.2 AI objectives. Budget most of your money for a question bank and none of it for a boot camp — the free lab material is where the actual learning happens on this exam.

ResourcePriceFormatBest for
Cisco 200-201 exam-topics PDF (official blueprint)FreePDF from Cisco Learning NetworkThe only authoritative statement of what v1.2 covers
CBROPS 200-201 Official Cert Guide (Cisco Press)~$60-70 listPrint + eBook with practice engineOrdered coverage of the five core domains
Cisco U. (free tier plus paid subscriptions)Free tier; subscriptions extraVideo, labs, practice assessmentsCisco-authored labs and the pre/post assessments
Cisco Networking Academy — Junior Cybersecurity Analyst pathFreeSelf-paced course with badgesStructure if you are starting without a SOC background
Boson ExSim-Max for Cisco 200-201$99 per exam titlePractice-exam engineDistractor-level explanations, the best readiness signal available
CBT Nuggets~$30-80/month by plan and billing termVideo subscriptionCandidates who need someone talking them through captures
Wireshark + public malware-traffic capture archivesFreeSelf-directed labDomain 4 — the highest-value free resource for this exam
Security Onion or Splunk FreeFreeSelf-hosted SIEM labDomain 2 monitoring, generating and hunting your own events
Exam voucher (200-201 CCNACBR)$300 USD, or Cisco Learning CreditsPearson VUERequired

Prices checked 2026-08 and shown as USD list price before tax; subscription tiers and Cisco Learning Credit rates change, so confirm at the vendor before purchase. We do not rank by commission.

Avoid these

What mistakes do candidates most often make?

The mistakes on this exam cluster into two groups: people who bought the wrong exam entirely, and people who studied it like a knowledge test instead of an analysis test.

Confusing CCNA Cybersecurity with CCNA 200-301

These are completely different certifications that now share a brand prefix, and the confusion got worse in February 2026 when Cisco renamed CyberOps Associate to CCNA Cybersecurity. CCNA 200-301 is routing, switching, IP services and automation. CCNA Cybersecurity is exam 200-201 CCNACBR, Understanding Cisco Cybersecurity Operations Fundamentals, and it is a SOC-analyst exam with no configuration content at all. Passing one does not count toward the other. Check the exam number on your voucher, not the certification name.

Studying from CyberOps-branded material without checking the v1.2 delta

The exam moved from v1.1 to v1.2 in January 2026 and the update was not cosmetic — it added AI-focused objectives across monitoring, threat intelligence and AI-specific risk. Every resource printed before 2026 misses them. Download the current exam topics from Cisco, list the objectives your book does not have a chapter for, and cover them separately. Your existing prep is not wasted, but it is incomplete.

Treating the exam as a vocabulary test

Candidates who pass consistently report that the hard items show them something — a log excerpt, a described capture, an alert with context — and ask for a judgement. Definition-level recall gets you through Domain 1 and abandons you in Domains 2 through 4. If your study time is more than two-thirds reading, rebalance it toward hands-on artefact work now.

Never opening a packet capture because "the exam has no simulations"

True, there are no lab simulations, and it is the wrong conclusion. The exam tests whether you can interpret evidence in a static presentation, and the only way to build that skill is to have handled the real thing. Working twenty public captures costs nothing but time and directly converts into Domain 4 points.

Assuming a CCNA or any other certification is a prerequisite

Cisco requires no prerequisite for 200-201 — you can book it as your first Cisco exam. That said, the exam assumes you can read an IP header and reason about TCP behaviour. If you cannot, the fix is a month of networking fundamentals, not a CCNA voucher. Do not spend $300 on 200-301 first out of a mistaken belief that you have to.

Booking with no plan for the 48-hour result wait

Cisco states that grading is pass/fail and results are available online within 48 hours, and its score reporting is far less granular than CompTIA's. Do not expect an immediate percentage breakdown to plan a retake around. Instead, write down the topic areas that felt weakest the moment you leave the centre — not the questions, which the NDA forbids you from recording — because that list will be more useful than anything Cisco sends you.

What you'll face

What question types will I see?

One hundred and twenty minutes, delivered in English, graded pass/fail. There are no configuration simulations on 200-201 — this is not a CLI exam — but that does not make it a multiple-choice memory test. The characteristic item presents evidence and asks for an analytical judgement: which data source answers this question, what does this process tree indicate, how should this alert be classified. Expect single-answer multiple choice as the bulk of the paper, multiple-response items that state how many options to select and score all-or-nothing, and drag-and-drop matching for things like kill chain phases, Diamond Model vertices and incident-response steps. A meaningful number of stems are exhibit-driven: a log excerpt, a table of flow records, a described capture. Cisco presents one question at a time and does not permit backward navigation, so budget time by checkpoint rather than planning to review at the end.

Single-answer multiple choiceMajority of items

Four to five options with a single correct answer. On this exam the distractors are almost always genuine analyst techniques that answer a subtly different question — the discrimination is about scope and access, not about right versus nonsense.

Multiple responseA minority of items

The stem specifies the count. Scored as a single unit, so two of three correct earns nothing. Common on data-source and evidence-handling objectives.

Drag and drop / matchingA minority of items

Match attack narratives to kill chain phases, artefacts to Diamond Model vertices, or place incident-response steps in order. Rewards ordered-list memorisation that pure multiple-choice practice skips.

Exhibit-based analysis itemsA substantial share of Domains 2-4

A log excerpt, flow table or capture summary is shown and you interpret it. These take disproportionate time — practise on real output so the format itself is not what slows you down.

Try these

Q1A SOC analyst must confirm whether a specific spreadsheet was actually transferred out of the network during a suspected exfiltration window. The organisation collects NetFlow from its edge routers, firewall connection logs, IDS alert data, and full packet capture at the internet egress. Which data source can answer the question?
  • A. NetFlow records, because they show the byte count of each conversation
  • B. Firewall connection logs, because they record the source, destination and duration of each session
  • C. Full packet capture, because it retains the payload and the file can be extracted and hashed
  • D. IDS alert data, because an exfiltration signature would have fired on the transfer

Answer:C

Only full packet capture retains payload. To confirm that a specific file left the network you have to reconstruct it from the stream and compare its hash to the original, which requires the bytes themselves. A and B are the tempting answers because both NetFlow and firewall logs will show that a large transfer occurred to that destination at that time — but they are metadata, and metadata can establish that something moved without establishing what. D is wrong because signature-based alerting fires on known patterns; the absence of an alert proves nothing about a novel or benign-looking transfer, and its presence would not identify the file.

Q2An IDS generates an alert for a SQL injection signature against an internal web application. Investigation shows the traffic originated from the security team's authorised vulnerability scanner during a scheduled scan window, and no malicious activity took place. How should the analyst classify this alert?
  • A. True positive
  • B. True negative
  • C. False positive
  • D. False negative

Answer:C

A false positive is an alert raised on activity that is not actually a security incident. The signature matched a real pattern in the traffic, but the underlying event was authorised testing, so the alert is not actionable and the classification is false positive. A is the trap: candidates reason that the signature correctly matched what it was written to match, so it must be a true positive. Classification in SOC practice is about whether the alert represents a genuine incident, not whether the pattern-matching worked. B describes correctly staying silent on benign traffic, which did not happen here. D describes malicious activity that produced no alert, which is the opposite situation.

Q3On a Linux web server, an analyst observes a bash process executing from /tmp with its parent process being the web server daemon, initiated shortly after an unusual POST request to an upload endpoint. What does this most likely indicate?
  • A. Routine package management activity, since package managers use temporary directories
  • B. A web shell, where an exploited web application is spawning a shell under its own service account
  • C. A scheduled cron job, since cron frequently executes scripts staged in temporary directories
  • D. A kernel module being loaded to support a newly attached device

Answer:B

The parent-child relationship is the whole answer. A web server daemon has no legitimate reason to spawn an interactive shell, and the correlation with a POST to an upload endpoint is the classic web-shell signature: attacker uploads a script through a file-handling flaw, then invokes it, and the resulting process inherits the web server's service account. A is tempting because package managers genuinely do use temporary directories, but their parent would be a package tool or a shell run by root, not httpd or nginx. C fails the same test — cron-launched processes have cron as the parent. D is unrelated: kernel module loading is not a bash process and would not descend from a web daemon.

Samples are editor-written illustrations of the published blueprint, not live exam items.

The big day

What should I expect on exam day?

Two hours in the chair, delivered through Pearson VUE at a test centre or online with OnVUE proctoring, in English only. This is long enough that fatigue becomes a real factor and short enough that there is no scheduled break — Cisco does not build breaks into a 120-minute exam, and the clock does not stop if you leave, so hydration and caffeine timing are genuine tactical decisions rather than fussiness. The single most important thing to internalise before you sit down is that Cisco presents questions one at a time and does not allow you to go back. On a paper with a substantial number of exhibit-driven analysis items, that means the instinct to skip the hard packet question and return to it later simply does not exist here. You must decide, commit and advance. Candidates who have only practised in an engine with flag-and-review lose ten to fifteen minutes rediscovering this on the day. Book a time of day when you are genuinely sharp; a 7pm slot after a full shift is a bad trade for a $300 exam.

Bring

  • A valid, unexpired government-issued photo ID with signature, name matching your Cisco registration exactly
  • A second form of ID with your name and signature — bring it whether or not you think your centre requires it
  • Your Cisco ID and Pearson VUE username
  • For OnVUE: a phone for check-in photos, a completely clear desk, and a private room with a door
  • For OnVUE: a system-tested webcam and connection, checked on the same machine and network you will use

Leave at home

  • Phones, smartwatches, fitness trackers, earbuds — locker at a centre, out of the room entirely for OnVUE
  • All notes, printouts and reference material; Cisco exams are strictly closed book
  • Your own paper and pens — centres issue an erasable noteboard and marker, and OnVUE gives you a digital whiteboard only, with no physical writing material permitted
  • Bags, coats, hats and food
  • Any second person; an OnVUE session is terminated if someone else appears on camera or is heard in the room

How the day runs

24-48 hours beforeFor OnVUE, complete the system test on the actual machine and network. For a centre, confirm the address and how long the journey really takes at that time of day.
30 minutes beforeArrive at the centre, or start OnVUE check-in. Online check-in involves photographing your face, your ID, and all four walls plus the desk surface, and typically runs about 15 minutes.
Check-inID verification, digital signature, biometric capture depending on the centre, and lockers. You are seated and issued an erasable noteboard.
First 3 minutes at the seatBefore starting, write your ordered lists on the noteboard: kill chain phases, NIST SP 800-61 IR lifecycle, order of volatility, and your data-source-to-question mapping. These are the items you do not want to be reconstructing at minute 100.
0-40 minutesFirst third. Aim to be roughly a third of the way through the item count. Exhibit items will run long; concept items should be quick, so bank time on them deliberately.
40-100 minutesMiddle stretch, where most of the artefact interpretation lands. Watch the clock every ten items. If you are behind, start making faster commitments on the exhibit questions — an educated commit beats an unanswered item, and there is no return path.
100-120 minutesFinal stretch. There is no review screen to fall back on, so the only defence against running out of time is having managed the first hundred minutes.
Immediately afterSurrender the noteboard, collect your belongings and leave. Do not discuss content with anyone; you accepted an NDA on screen before question one.

Rules in the room

  • Cisco exams do not permit backward navigation — you cannot flag, skip or return to an item.
  • Grading is pass/fail and Cisco states results are available online within 48 hours; the cut score is not published.
  • No scheduled breaks on a 120-minute exam, and the timer continues if you leave the room.
  • The exam is delivered in English only.
  • The erasable noteboard is provided and must be surrendered; you may not bring your own paper, and OnVUE candidates get a digital whiteboard only.
  • Fail and you must wait five calendar days from the day after your attempt before retesting, at the full $300 fee.
  • Pass and you must wait a minimum of 180 days before sitting the same exam number again.

Afterwards.Cisco grades 200-201 pass/fail and states that results are available online within 48 hours, so do not build your plans around an immediate detailed breakdown the way a CompTIA candidate would. Check the Cisco Certification Tracking System for your official status and, once posted, claim the digital badge through Credly. A pass earns CCNA Cybersecurity, valid for three years; you renew by earning 30 Continuing Education credits, by re-taking a qualifying exam, or by passing any higher-level exam, and Cisco explicitly notes that 200-201 itself can be used toward recertification of other credentials. If you fail, the five-day wait starts the day after your attempt, and the most productive thing you can do in that window is rebuild your weakest domain from primary material rather than grinding the same question bank that already told you what you knew. Write your subject-area impressions down within an hour of finishing — memory of which topics felt shaky decays fast, and Cisco will not give you a granular enough report to reconstruct it later.

Reference

What are the key facts about the Cisco Certified Network Associate Cybersecurity?

Cisco Certified Network Associate Cybersecurity is a certification credential; awarded by Cisco Systems; the exam fee is US$300 (plus applicable tax; regional pricing may differ). Redeemable with Cisco Learning Credits.; typical preparation is Approximately 2-4 months of part-time study (about 80-120 hours)..

CredentialCisco Certified Network Associate Cybersecurity
AbbreviationCCNA Cybersecurity
TypeCertification
ProfessionIT, Cloud & Cybersecurity
SpecialtyCisco
Awarded byCisco Systems
DifficultyModerate
Typical prep timeApproximately 2-4 months of part-time study (about 80-120 hours).
All-in costUS$300 (exam); optional training US$0-$900.
CredentialCisco Certified Network Associate (CCNA) Cybersecurity
Exam code200-201 CBROPS (Understanding Cisco Cybersecurity Operations Fundamentals)
LevelAssociate (successor to CyberOps Associate)
Duration / Questions120 minutes / ~95-105 questions
Exam feeUS$300
Validity3 years
ScopeNational / Multi-state
Also known as200-201, CBROPS, Cisco Certified CyberOps Associate

Real questions

Frequently asked questions about the Cisco Certified Network Associate Cybersecurity

What is the difference between CCNA Cybersecurity and the old CyberOps Associate?

They are the same certification lineage. The 200-201 CBROPS exam now feeds the associate-level Cisco cybersecurity credential (commonly referenced as CCNA Cybersecurity), which replaced the former 'Cisco Certified CyberOps Associate' branding. The exam content and weightings are unchanged.

How many questions are on the 200-201 exam and how long do I have?

The exam is 120 minutes with roughly 95-105 questions, mixing multiple-choice, multiple-response, drag-and-drop, and short scenario items where you interpret logs or packet data. No hands-on simulator is included.

What score do I need to pass, and will I see my score?

Cisco does not publish a fixed passing number. Results use a scaled 300-1000 range and the statistical cut score typically lands near 750-850. You get a pass/fail result on screen plus a section-level performance summary.

Do I need to pass a core plus a concentration like CCNP?

No. Unlike CCNP tracks, the associate cybersecurity credential requires only the single 200-201 CBROPS exam. Pass it and you hold the certification.

What jobs can I get with CCNA Cybersecurity?

Typical roles include SOC Analyst (Tier 1), Junior Security Analyst, Threat Analyst, and Security Operations Technician. It is also a recognized stepping stone toward CCNP Security and CCIE Security.

How long is a Cisco certification valid, and how do I renew it?

Every Cisco certification is valid for 3 years. You can recertify by passing a qualifying exam at or above the current level, by earning Continuing Education credits, or by combining both before the expiry date.

Where do I take Cisco exams and what ID do I need?

Cisco exams are delivered by Pearson VUE at test centers or online via OnVUE (CCST via Certiport/Pearson VUE). You must present a valid government-issued photo ID; online exams also require a room/environment scan.

What happens if I fail a Cisco exam?

You must wait 5 calendar days before retaking the same exam, and each retake requires paying the full exam fee again. Your score report shows section-level feedback to guide further study.

In short

Is the Cisco Certified Network Associate Cybersecurity worth it?

  • Single-exam associate cybersecurity certification (200-201 CBROPS), 120 minutes, ~95-105 questions, US$300.
  • Five weighted domains - Security Monitoring is the heaviest at 25%; policies/procedures the lightest at 15%.
  • No formal prerequisite; maps to NICE framework SOC Tier-1 analyst tasks.
  • Valid 3 years; pairs naturally with CCNP Security as the next step.

Same awarding body

What other credentials does Cisco Systems award?

Trust

Where does this information come from?

Everything above is taken from the awarding body's own published material. Fees, question counts and domain weights are revised regularly — check the official page before you pay.

Research confidence: high · Last reviewed 2026-08

How this guide is maintained

Cloud, IT & cybersecurity certifications desk

This guide is compiled and maintained by our IT-certifications desk. Vendor exams in this space are revised and retired frequently, so we track the objectives document by its published revision date and state plainly when an exam is being retired and what replaces it — the single most common way candidates waste money here is studying a superseded blueprint. Fees, scoring, retake rules and renewal terms come from the vendor’s own certification pages. Wage figures come from the Bureau of Labor Statistics occupational series closest to the role, named by SOC code, with the caveat that BLS classifies by job duties rather than by certificate.

Objectives, exam codes, fees and retirement dates were taken from the vendor’s current certification pages and checked for the revision date shown there. Every fee, score and deadline on this page was checked against the primary sources cited above in August 2026. Exam boards change these without notice — confirm anything you are about to pay for on the official site.