
Cisco Certified CyberOps Associate
The Cisco Certified CyberOps Associate certification validates your ability to detect and respond to cybersecurity threats as part of a Security Operations Center (SOC) team. This certification is for security analysts and SOC practitioners who monitor, analyze, and investigate security events. Earning it demonstrates that you have the foundational skills to protect your organization's digital assets and advance your cybersecurity career.
1812 practice questions · Updated 2026-07-30
5Domains
50Objectives
330Concepts
1812Questions
200-201 Curriculum
Every domain, objective, and concept the 200-201 exam measures.
- Confidentiality
- Integrity
- Availability
- CIA Triad Interplay
- Network security systems
- Endpoint security systems
- Application security systems
- Agentless protections
- Agent-based protections
- Legacy antivirus
- Antimalware solutions
- SIEM
- SOAR
- Log management
- Container security
- Virtual environment security
- Cloud security deployments
- Cloud security controls
- Threat Intelligence (TI)
- Threat Hunting
- Malware Analysis
- Threat Actor
- Run Book Automation (RBA)
- Reverse Engineering
- Sliding Window Anomaly Detection
- Threat Modeling
- DevSecOps
- Risk
- Risk Scoring and Weighting
- Risk Reduction
- Risk Assessment
- Threat
- Vulnerability
- Exploit
- Defense-in-depth overview
- Layered security controls
- Defense-in-depth principles
- Application to network security
- Application to host security
- Application to application and data security
- Benefits and limitations
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Nondiscretionary Access Control
- Authentication, Authorization, and Accounting (AAA)
- Rule-Based Access Control
- Time-Based Access Control
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- CVSS Overview
- Attack Vector (CVSS)
- Attack Complexity (CVSS)
- Privileges Required (CVSS)
- User Interaction (CVSS)
- Scope (CVSS)
- Temporal Metrics (CVSS)
- Environmental Metrics (CVSS)
- Data visibility challenges in network
- Data visibility challenges in host
- Data visibility challenges in cloud
- Impact of visibility gaps on detection
- Traffic profiling fundamentals
- Data loss indicators in traffic
- Common data loss vectors
- Analyzing traffic profiles for anomalies
- Correlating traffic with data loss events
- 5-tuple definition
- Log grouping by 5-tuple
- Isolating compromised host
- Interpreting grouped logs
- Rule-based detection
- Behavioral detection
- Statistical detection
- Comparison of detection methods
- Attack surface definition
- Attack surface components
- Vulnerability definition
- Attack surface vs. vulnerability
- Attack surface reduction
- Vulnerability management
- TCP dump data types
- NetFlow data types
- Next-gen firewall data types
- Traditional stateful firewall data types
- Application visibility and control data types
- Web content filtering data types
- Email content filtering data types
- Access Control List (ACL) Impact on Data Visibility
- NAT/PAT Impact on Data Visibility
- Tunneling Impact on Data Visibility
- TOR Impact on Data Visibility
- Encryption Impact on Data Visibility
- P2P Impact on Data Visibility
- Encapsulation Impact on Data Visibility
- Load Balancing Impact on Data Visibility
- Full packet capture
- Session data
- Transaction data
- Statistical data
- Metadata
- Alert data
- Protocol-based attacks
- Denial of Service (DoS) attacks
- Distributed Denial of Service (DDoS) attacks
- Man-in-the-middle (MITM) attacks
- SQL injection
- Command injection
- Cross-site scripting (XSS)
- Social Engineering Fundamentals
- Common Social Engineering Techniques
- Manual Social Engineering Attacks
- Generative AI in Social Engineering
- AI-Generated Content Detection
- Mitigation and Defense
- Buffer Overflow Fundamentals
- Buffer Overflow Exploitation and Impact
- Command and Control (C2) Basics
- C2 Communication and Evasion
- Malware Types and Characteristics
- Malware Infection Vectors
- Ransomware Attack Lifecycle
- Ransomware Impact and Mitigation
- Tunneling
- Encryption
- Proxies
- PKI fundamentals
- Certificate lifecycle
- Public and private key crossing the network
- Asymmetric vs symmetric encryption
- Certificate impact on security
- Cipher-suite components
- X.509 certificate structure
- Certificate chain and validation
- Key exchange methods
- Protocol version identification
- PKCS standards
- Host-Based Intrusion Detection Systems (HIDS)
- HIDS Rules and Signatures
- Antimalware and Antivirus Mechanisms
- Signature-Based Detection
- Heuristic and Behavioral Detection
- Host-Based Firewall Functionality
- Host-Based Firewall Rules
- Predictive AI in Endpoint Security
- OS architecture overview
- Windows OS components
- Linux OS components
- Process and memory management
- File system and permissions
- User and privilege management
- OS logs and auditing
- Interpreting OS components in scenarios
- Asset Identification
- Threat Actor Profiling
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Chain of Custody Principles
- Best evidence
- Corroborative evidence
- Indirect evidence
- Log Interpretation Fundamentals
- Operating System Logs
- SIEM Log Analysis
- SOAR Platform Logs
- Application Logs
- Command Line Logs
- Event Identification
- Purpose of detonation chambers and sandboxes
- Key sections of a sandbox report
- Interpreting file and process activity
- Interpreting network activity
- Identifying indicators of compromise (IOCs)
- Correlating report findings with malware behavior
- Limitations of sandbox analysis
- Hash Functions and Properties
- Common Hash Algorithms
- Hash Verification and Integrity
- Hash Analysis in Threat Hunting
- URL Structure and Components
- URL Obfuscation Techniques
- URL Reputation and Analysis
- URL Extraction and Decoding
- System Event Logs
- Network Event Logs
- Event Correlation and Attribution
- Log Sources and Collection
- IDS/IPS event mapping
- Firewall event mapping
- Network application control event mapping
- Proxy log event mapping
- Antivirus event mapping
- Transaction data (NetFlow) event mapping
- Definition of True Positive
- Definition of True Negative
- Definition of False Positive
- Definition of False Negative
- Definition of Benign
- Impact vs No Impact Classification
- Impact of False Positives
- Impact of False Negatives
- Impact of True Positives and True Negatives
- Impact of Benign Events
- Comparing Impact and No Impact
- Deep Packet Inspection (DPI)
- Packet Filtering
- Stateful Firewall Operation
- Comparison of DPI, Packet Filtering, and Stateful Firewalls
- Inline traffic interrogation
- Taps and traffic monitoring
- Comparison of inline and tap-based monitoring
- Use cases for inline interrogation
- Use cases for taps and traffic monitoring
- TAP vs SPAN port data characteristics
- NetFlow transactional data characteristics
- Comparison of visibility and granularity
- Use cases for taps and NetFlow in analysis
- Impact on storage and processing resources
- PCAP file basics
- Wireshark interface navigation
- TCP stream identification
- Following TCP streams
- Extracting raw stream data
- Handling binary and text data
- File carving from streams
- Verifying extracted files
- PCAP file structure
- Source address extraction
- Destination address extraction
- Source port identification
- Destination port identification
- Protocol identification
- Payload analysis
- Source and Destination IP Addresses
- Client and Server Port Identity
- Process Identification (File or Registry)
- System API Calls
- Hash Values
- URI and URL Analysis
- Regex syntax basics
- Character classes
- Quantifiers
- Anchors and boundaries
- Alternation and grouping
- Escaping special characters
- Applying regex to network data
- Asset Management
- Asset Lifecycle
- Configuration Management
- Configuration Baseline
- Mobile Device Management
- MDM Enrollment and Policies
- Patch Management
- Patch Management Process
- Vulnerability Management
- Vulnerability Scanning and Assessment
- Remediation and Mitigation
- NIST SP 800-61 Overview
- Incident Response Plan Elements
- Incident Response Policy
- Procedures and Playbooks
- Roles and Responsibilities
- Communication Plan
- Incident Handling Process
- Preparation Phase
- Detection and Analysis Phase
- Containment, Eradication, and Recovery Phase
- Post-Incident Activity Phase
- Coordination and Information Sharing
- NIST SP 800-61 Incident Handling Lifecycle
- Incident vs. Event Distinction
- Incident Detection and Analysis
- Incident Containment Strategies
- Eradication and Recovery Procedures
- Post-Incident Activity and Lessons Learned
- Incident Handling Documentation
- Incident Response Team Roles and Communication
- Preparation
- Detection and Analysis
- Containment, Eradication, and Recovery
- Post-Incident Analysis (Lessons Learned)
- NIST IR lifecycle phases
- Preparation phase stakeholders
- Detection and analysis stakeholders
- Containment, eradication, and recovery stakeholders
- Post-incident analysis stakeholders
- CMMC stakeholder mapping
- NIST SP 800-61 stakeholder roles
- Evidence Collection Order
- Data Integrity
- Data Preservation
- Volatile Data Collection
- Total throughput
- Session duration
- Ports used
- Critical asset address space
- Listening ports
- Logged in users and service accounts
- Running processes
- Running tasks
- Applications
- PII Definition
- PII Protection
- PSI Definition
- PSI Handling
- PHI Definition
- PHI Regulations
- Intellectual Property Definition
- Intellectual Property Protection
- Cyber Kill Chain Model
- Diamond Model of Intrusion
- Event Classification Using Cyber Kill Chain
- Event Classification Using Diamond Model
- Comparison of Security Models
- SOC metrics definition
- Scope analysis in SOC
- Time to detect (TTD)
- Time to respond (TTR)
- Time to contain (TTC)
- Time to control (TTCO)
- Relationship of metrics to scope analysis
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 200-201, so none is invented.