200-201 · ● Active · Associate · Cisco
Latest update (Feb 2026): The 200-201 CBROPS exam was officially rebranded as CCNA Cybersecurity (200-201 CCNACBR) v1.2, adding AI and AI-generated threat detection topics. Exam code remains 200-201; content aligns with SOC-focused cybersecurity operations.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $300 |
| Duration | 120 minutes |
| Questions | 95–105 (mixed format) |
| Passing | Scaled score ~825/1000 |
| Format | Multiple choice, multiple response, drag-and-drop, fill-in-the-blank |
| Delivery | Pearson VUE (in-person or online proctored) |
| Languages | English; Japanese (select regions) |
| Valid | 3 years |
| Renewal | CE credits or pass higher Cisco security cert (CCNP Security) |
| Prerequisites | None; foundational networking + security knowledge recommended |
| Released | 2018 (current v1.2 released Feb 2026) |
| Retiring | N/A (actively maintained) |
Vendor source — Cisco CyberOps Associate ↗
Exam objectives — Cisco Learning Network 200-201 CCNACBR Topics ↗
Official exam guide — Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide ↗
About
The Cisco Certified CyberOps Associate (200-201) is Cisco's associate-level cybersecurity certification designed to validate knowledge and hands-on skills for security operations center (SOC) professionals. Launched in 2018 and rebranded to CCNA Cybersecurity (200-201 CCNACBR) in February 2026, the cert bridges entry-level security technicians and SOC analysts into mid-career security engineering roles. The exam covers security monitoring, host-based and network intrusion analysis, incident response, and security policies—all critical in defensive SOC environments. As of v1.2 (2026), the exam adds AI-generated threat detection, AI-assisted security tool operation, and AI security risks. No prerequisites required, making it accessible to IT professionals with networking fundamentals. Valid 3 years; renewal via CCNP Security or continuing education credits.
Domain context — Security / SOC Operations
Security operations encompasses network defense, endpoint protection, incident response, and threat intelligence across enterprise and hybrid environments. SOC-focused roles require mastery of detection tools (SIEM, IDS/IPS), log analysis, incident triage, and evidence handling.
Read full deep dive — Cisco Ecosystem →
Topics covered
Exam v1.2 (February 2026) validates knowledge across five domains with AI elements integrated:
- Security Concepts (20%) — CIA triad, threat landscape, attack vectors, defense-in-depth, cryptography (symmetric, asymmetric, hashing, SSL/TLS), authentication models (LDAP, Radius, Tacacs+)
- Security Monitoring (25%) — SIEM platforms (Splunk, Elasticsearch), NetFlow, syslog, network traffic analysis, log aggregation, alert tuning, baseline establishment, sensor deployment
- Host-Based Analysis (20%) — Endpoint Detection and Response (EDR) tools, malware analysis, process monitoring, file integrity, registry analysis, volatile memory forensics, indicator of compromise (IOC) identification
- Network Intrusion Analysis (20%) — IDS/IPS operations, packet analysis (tcpdump, Wireshark), protocol behavior, signature vs. anomaly detection, flow analysis, network segmentation, DMZ concepts, firewall rule interpretation
- Security Policies and Procedures (15%) — Incident response procedures, chain of custody, containment / eradication / recovery, playbook execution, compliance frameworks (PCI-DSS, GDPR basics), security awareness, evidence preservation, escalation protocols
- AI in Security (Embedded across all domains) — AI-generated threat detection, AI tool integration (threat intelligence automation), AI security risks and mitigations
Source: Cisco Learning Network CCNA Cybersecurity v1.2 Topics ↗
Common skills at Security · Associate
Shared cybersecurity operations skills at Associate level — not specific to this cert.
- Threat triage and escalation — Classifying alerts by severity, filtering false positives, escalating confirmed threats
- Log interpretation — Parsing syslog, Windows Event Log, firewall logs, identifying anomalies and indicators of compromise
- Incident response execution — Following documented playbooks, containment, evidence collection, post-incident documentation
- SIEM fundamentals — Dashboard creation, search query syntax, correlation rule basics, alert management
- Packet analysis — Understanding packet structure, identifying malicious traffic patterns, protocol anomalies
- Communication and documentation — Briefing team members, incident tickets, chain of custody paperwork
- Tool familiarity — Operating IDS/IPS, EDR consoles, SIEM interfaces, network analyzers, command-line forensics tools
Recommended courses at Security · Associate
| Provider | Title | Cost | URL |
|---|---|---|---|
| Cisco Networking Academy | CyberOps Associate (official curriculum) | Free (via partner institutions) or $300–600/year | ↗ |
| CBT Nuggets | CCNA Cybersecurity 200-201 (Keith Barker et al.) | $300–$600/yr subscription | ↗ |
| Udemy | Cisco Certified CyberOps Associate 200-201 (multiple instructors) | $15–$100 | ↗ |
| INE | CyberOps Associate (200-201) on-demand | $199–$399 | ↗ |
| YouTube: Jeremy's IT Lab | CyberOps Associate deep-dive series (free + paid) | Free (YouTube) + $10–$15/mo (patreon) | ↗ |
| LinkedIn Learning | Cisco CyberOps Associate Cert Prep | $30–$40/mo | ↗ |
| Pluralsight | Cisco CyberOps Associate Learning Path | $299+/yr | ↗ |
Course-selection rule: Cisco Networking Academy curriculum directly maps to exam objectives and is the gold-standard reference; CBT Nuggets (Keith Barker) and Udemy instructors provide accessible deep-dives; INE and Jeremy's IT Lab are preferred by hands-on learners; LinkedIn Learning suits busy professionals.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Pearson Test Prep | Cisco CyberOps Associate 200-201 Official Practice Test (4 full exams) | $99–$129 | ↗ |
| Whizlabs | Cisco CyberOps Associate (200-201) Practice Exams | $79–$99 | ↗ |
| MeasureUp | Cisco 200-201 CBROPS Practice Test | $99–$129 | ↗ |
| Cisco Learning Network | Official practice questions (limited free + paid) | Free (limited) – $50 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Cisco Cybersecurity Operations Fundamentals CBROPS 200-201 Official Cert Guide | Omar Santos | Cisco Press | 2020 | 978-0-13-680783-4 | ↗ |
| CompTIA Security+ SY0-701 Study Guide | Mike Chapple, David Seidl | Sybex (Wiley) | 2024 | 978-1-39-424907-7 | ↗ |
Book note: The official Cisco Press guide by Omar Santos is the primary reference and maps directly to exam blueprint v1.2. The CompTIA Security+ guide is supplementary—both certs share foundational security principles (CIA triad, incident response, cryptography basics) and cross-studying reinforces core concepts. Consider the Cisco official guide as mandatory; Security+ study guide as optional reinforcement.
Typical job titles at Security · Associate
SOC Analyst Tier 1 (L1) · Security Analyst · Cybersecurity Analyst · Junior SOC Engineer · Incident Response Technician · Security Operations Specialist · Threat Analyst (Entry) · Security Support Technician
(Job titles drawn from current job-board postings and Cisco Learning Network forums listing 200-201 / CyberOps as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $65K–$95K (SOC L1/Analyst median) | Glassdoor 2026 ↗ · Coursera 2026 ↗ |
| ZAR | R400K–R700K (cybersecurity analyst) | PayScale ZA 2026 ↗ · SalaryExpert Johannesburg ↗ |
| GBP | £40K–£65K (cybersecurity analyst entry) | Indeed UK ↗ · Bristow Holland 2026 ↗ |
Salary context: SOC L1 analysts in the US earn $65K–$95K median (top quartile $120K+); premium markets (NYC, SF, DC) reach $110K–$130K. ZAR data: R400K–R700K range reflects South African mid-market (Johannesburg/Cape Town); entry analysts start ~R300K, seniors exceed R900K. UK rates depend on location: London £50K–£80K, Edinburgh/Manchester £35K–£55K. Premium certifications (CCNP Security, GCIH, GIAC) and hands-on experience (2+ years SOC) unlock $120K+ (USD) or equivalent salary bands.
Skills validated
Cert-specific — what the 200-201 exam tests, distinct from shared Associate-level skills.
- SIEM platform operation — Alert tuning, saved searches, dashboard design (Splunk-style environment), log correlation, anomaly detection threshold setting
- Network traffic analysis — Packet inspection (tcpdump, Wireshark), protocol behavior identification, traffic baseline deviation detection, suspicious flow patterns
- Host forensics — Process execution trees, file behavior analysis, registry inspection, memory dump analysis, persistence mechanism identification
- IDS/IPS alert interpretation — Signature-based detection understanding, false-positive tuning, evasion technique recognition, alert prioritization
- Incident response execution — Playbook-driven containment, evidence preservation (chain of custody), triage severity assessment, escalation decision-making
- Cryptography application — SSL/TLS handshake concepts, symmetric vs. asymmetric encryption use cases, digital signatures, key management awareness
- Security tool scripting awareness — Basic log parsing, automation concept familiarity, API-driven threat intelligence integration, alert automation
- AI-augmented detection — AI tool integration (ChatGPT for threat intelligence writing, AI-based anomaly detection systems), AI threat generation (deepfakes, AI-generated phishing), AI security risk mitigation
Related certifications
- Prerequisite for: Cisco CCNP Security (SCOR 350-701) ↗ (professional-level network security engineering; requires 200-201 + concentration exam)
- Entry-level alternative: CompTIA Security+ SY0-701 ↗ (vendor-neutral foundational cert; overlaps in CIA triad, incident response, encryption concepts)
- Complementary cert: CompTIA CySA+ CS0-003 ↗ (threat hunting + vulnerability management focus)
- Stacks with: Cisco CCST Cybersecurity 100-160 ↗ (entry-level; CyberOps is the natural progression)
- Vendor overview: Cisco Vendor Overview
Sources
- Cisco CyberOps Associate Exam Page: https://www.cisco.com/site/us/en/learn/training-certifications/exams/ccnacbr.html
- Cisco Learning Network 200-201 Topics: https://learningnetwork.cisco.com/s/cyberops-associate
- Cisco Press Official Cert Guide: https://www.ciscopress.com/store/cisco-cybersecurity-operations-fundamentals-cbrops-9780136807834
- Pearson Test Prep Practice Exams: https://govstore.pearsonvue.com/cisco-cyberops-associate-cbrops-200-201-official-cert-guide-premium-edition-and-practice-test-ebook-/p/978-0-13-691764-9
- Whizlabs Practice Exams: https://www.whizlabs.com
- CBT Nuggets CyberOps Course: https://www.cbtnuggets.com/it-training/cisco/cyberops-associate
- Cisco Networking Academy: https://www.netacad.com/courses/cyberops-associate
- Glassdoor SOC Analyst Salary 2026: https://www.glassdoor.com/Salaries/soc-analyst-salary-SRCH_KO0,11.htm
- Coursera SOC Analyst Salary Guide 2026: https://www.coursera.org/articles/soc-analyst-salary
- PayScale ZA Cybersecurity Analyst: https://www.payscale.com/research/ZA/Job=Cyber_Security_Analyst/Salary
- UK Indeed Cybersecurity Analyst Salaries: https://uk.indeed.com/career/cybersecurity-analyst/salaries
- Bristow Holland UK Salary 2026: https://www.bristowholland.com/insights/industry-insights/uk-cybersecurity-analyst-salary-expectations-in-2026-hiring-trends-and-workforce-planning/
- CompTIA Security+ vs Cisco CyberOps: https://www.newhorizons.com/resources/blog/cisco-cyber-ops-vs-comptia-security
Last verified: 2026-05-01
Parent ecosystem: Cisco Ecosystem
Parent domain: Security Domain
Vendor overview: Cisco Vendor Overview
Study approach (10–14 week timeline)
Week 1–2: Foundations and diagnostics
- Read Cisco exam blueprint from Learning Network.
- Watch Cisco Networking Academy Introduction to CyberOps (free, 1–2 hours overview).
- Take diagnostic quiz; identify weak areas (SIEM? packet analysis? incident response?).
- Set up lab environment: GNS3, Cisco Packet Tracer, or Networking Academy labs.
Week 3–4: Core content—fundamentals
- Complete Cisco Networking Academy CyberOps Associate course Module 1–4 (security concepts, monitoring basics).
- Watch CBT Nuggets domains 1–2 (security concepts, SIEM fundamentals).
- Read Cisco Press official guide chapters 1–5 (CIA triad, threat modeling, cryptography, authentication, SIEM architecture).
- Lab: Deploy a basic Splunk instance or review Cisco Networking Academy SIEM simulator; execute sample searches.
Week 5–6: Deep-dive—detection and analysis
- Complete Cisco Networking Academy modules 5–8 (network analysis, host-based analysis, packet analysis).
- Watch CBT Nuggets domains 3–4 (IDS/IPS, packet capture, Wireshark hands-on).
- Read Cisco Press chapters 6–10 (network security, IDS/IPS, malware analysis, EDR tools).
- Lab: Capture live traffic (tcpdump), analyze in Wireshark, identify anomalies. Practice Splunk search queries on sample logs. Analyze PCAPs of known malware traffic.
Week 7–8: Hands-on incident response
- Complete Cisco Networking Academy incident response modules.
- Watch CBT Nuggets domain 5 (incident response procedures, playbooks, chain of custody).
- Read Cisco Press chapters 11–13 (incident response, forensics, policies).
- Lab: Simulate incident response: triage alert → escalate → contain → preserve evidence. Practice playbook execution using sample SIEM alerts. Document chain of custody.
Week 9–10: AI and emerging threats
- Study v1.2 AI topics: AI-generated threat detection, AI tool integration, AI security risks.
- Watch supplemental resources on AI security (vendor blogs, YouTube channels covering AI threats).
- Review case studies: AI-generated phishing, deepfake detection, automated threat hunting.
- Lab: Experiment with AI-augmented SIEM features (if available in test environment); practice threat intelligence automation.
Week 11–12: Practice exams and review
- Take Pearson Test Prep full-length practice exam 1 (target 75%+).
- Review all incorrect answers; note knowledge gaps (e.g., "weak on IPS rule tuning").
- Take practice exam 2 (Whizlabs) one week later; aim for 80%+.
- Flashcard review: key SIEM queries, IDS/IPS signatures, incident response steps, cryptographic algorithms, AI threat scenarios.
Week 13: Final review and confidence building
- Take Pearson full-length exam 3; review weak areas.
- Review exam blueprint one more time; ensure all domains covered.
- Hands-on: re-do 2–3 critical labs (Wireshark analysis, SIEM search query optimization, incident response playbook).
- Mock exam conditions: 120 minutes uninterrupted, same question mix.
Week 14: Exam day prep
- Light review (30 min) day before: review quick reference sheets, key definitions.
- Exam day: arrive early, review exam policies, read all questions carefully, flag uncertain items for review at end.
Study time estimate: 100–150 hours (including coursework, hands-on labs, practice exams, reading). Realistic timeline for working professionals: 12–16 weeks part-time (8–10 hrs/week).
Lab setup (free / low-cost options):
- Cisco Networking Academy labs — Included in academy enrollment (best for beginners).
- GNS3 — Free network simulator (suitable for network intrusion analysis practice).
- Wireshark — Free packet analyzer (essential for traffic analysis).
- VirtualBox — Free hypervisor (for running Windows/Linux test environments, malware analysis VMs).
- Splunk Free — 500MB/day limit; sufficient for learning SIEM basics.
- OWASP WebGoat — Free vulnerable web app for hands-on exploitation (complements SOC analysis).
Study guide compiled for comprehensive 200-201 preparation. Adjust pace based on prior security experience and available study time.