
Cisco Certified Network Professional Cybersecurity (CBRCOR)
The Cisco Certified Network Professional Cybersecurity (CBRCOR) certification validates your expertise in core cybersecurity operations, covering fundamentals, techniques, processes, and automation. It is designed for security professionals who protect networks and data in complex environments. Earning this credential demonstrates your ability to address nuanced security challenges and elevates your career in the growing cybersecurity field.
2075 practice questions · Updated 2026-07-30
4Domains
58Objectives
384Concepts
2075Questions
350-201 Curriculum
Every domain, objective, and concept the 350-201 exam measures.
- Playbook Structure
- Playbook Components
- Playbook Interpretation
- Playbook Workflow Analysis
- Playbook Analysis
- Tool Selection Criteria
- Tool Categorization
- Scenario-to-Tool Mapping
- Playbook fundamentals
- Unauthorized elevation of privilege scenario
- DoS and DDoS scenario
- Website defacement scenario
- Common playbook phases
- Scenario-specific actions
- PCI DSS
- FISMA
- FedRAMP
- SOC
- SOX
- GDPR
- Data Privacy
- ISO 27101
- Cyber Risk Insurance Overview
- Coverage Types
- Policy Components
- Risk Assessment and Underwriting
- Impact on Security Posture
- Asset Identification
- Vulnerability Assessment
- Threat Identification
- Risk Analysis Methods
- Risk Calculation
- Risk Prioritization
- Incident Response Phases
- Preparation Activities
- Detection and Analysis
- Containment Strategies
- Eradication and Recovery
- Post-Incident Activities
- Evidence Handling and Chain of Custody
- Communication and Coordination
- Incident response metrics overview
- Mean time to detect (MTTD)
- Mean time to respond (MTTR)
- Mean time to contain (MTTC)
- Mean time to resolve (MTTR)
- Mean time to recover (MTTR)
- Time to acknowledge (TTA)
- Time to triage (TTT)
- Time to investigate (TTI)
- Time to eradicate (TTE)
- Time to recover (TTR)
- Incident cost metrics
- Effectiveness metrics
- Areas for improvement using metrics
- Benchmarking and trend analysis
- Cloud deployment models
- Cloud service models
- Multi-cloud and hybrid cloud
- Cloud characteristics
- Cloud security considerations
- IaaS security responsibilities
- PaaS security responsibilities
- Shared responsibility model
- Cloud security controls
- Operational security considerations
- AI-powered data analytics overview
- Use cases for AI analytics
- Matching analytics to questions
- Supervised vs unsupervised learning
- Classification techniques
- Clustering techniques
- Regression techniques
- Anomaly detection techniques
- Natural language processing (NLP)
- Time-series analysis
- Graph analytics
- Ensemble methods
- Model evaluation and validation
- Data preprocessing for AI
- Interpreting AI results
- Limitations and considerations
- Hardening machine images
- Image hardening techniques
- Deployment considerations
- Asset Security Posture Evaluation Process
- Asset Identification and Classification
- Threat and Vulnerability Assessment
- Security Controls Evaluation
- Risk Analysis and Scoring
- Posture Reporting and Remediation
- Security Control Evaluation
- Gap Analysis
- Control Recommendations
- Identify industry standards for system hardening
- Determine hardening recommendations for operating systems
- Determine hardening recommendations for network devices
- Determine hardening recommendations for applications
- Determine hardening recommendations for cloud environments
- Apply hardening standards to real-world scenarios
- Identify vulnerability context
- Prioritize patches by risk
- Apply patch management best practices
- Consider system constraints
- Verify patch effectiveness
- Identify unnecessary services
- Assess service risk
- Recommend disabling services
- Justify service disablement
- Consider operational impact
- Segmentation Principles
- Segmentation Strategies
- Segmentation Implementation
- Segmentation Enforcement
- Segmentation Verification
- Network Segmentation
- Access Control Lists (ACLs)
- Port Security
- DHCP Snooping
- Dynamic ARP Inspection (DAI)
- IP Source Guard
- Control Plane Policing (CoPP)
- Network Device Hardening
- Encryption Protocols
- Network Monitoring and Logging
- DevSecOps principles
- Security in CI/CD pipelines
- Infrastructure as Code (IaC) security
- Automated security testing
- Container and orchestration security
- Compliance and governance in DevSecOps
- Incident response in DevSecOps
- Toolchain integration
- AI-driven threat intelligence fundamentals
- AI-powered threat intelligence platforms
- Applying AI for threat detection and analysis
- Integrating AI threat intelligence into security operations
- Evaluating AI threat intelligence effectiveness
- Data Loss vs. Data Leakage
- Data States: At Rest, In Motion, In Use
- Common Standards for Data Protection
- Applying Protections Based on Data State
- Host-based DLP mechanisms
- Network-based DLP mechanisms
- Application-based DLP mechanisms
- Cloud-based DLP mechanisms
- Tuning device rules
- Adapting filters
- Policy adjustment
- Rule lifecycle management
- Baseline and anomaly comparison
- Feedback integration
- Security Data Sources
- Data Collection Methods
- Data Normalization
- Data Correlation
- Data Enrichment
- Data Storage and Retention
- Data Lifecycle Management
- Data Privacy and Compliance
- Data Analytics and Visualization
- SIEM fundamentals
- Security data sources
- Log collection and normalization
- Correlation rules and analytics
- Threat intelligence integration
- Dashboards and reporting
- Incident investigation and response
- SIEM deployment and maintenance
- Incident Escalation Procedures
- SOAR Workflow Fundamentals
- Playbook Design for Incident Response
- Automation of Response Actions
- Integration of Tools and Systems
- Workflow Triggers and Conditions
- Human-in-the-Loop Decision Points
- Metrics and Reporting for Workflow Effectiveness
- Dashboard Data Interpretation
- Audience-Specific Communication
- Executive Summarization
- Technical Detail Presentation
- Leadership Decision Support
- UEBA fundamentals
- SIEM data sources for UEBA
- Baseline behavior modeling
- Anomaly detection techniques
- UEBA alerts and risk scoring
- Investigating UEBA alerts
- Response actions for UEBA findings
- User behavior alert interpretation
- Alert triage and prioritization
- Response action selection
- Contextual analysis of user behavior
- Incident response decision-making
- Packet capture tools
- Limitations of packet capture tools
- Traffic analysis tools
- Limitations of traffic analysis tools
- Network log analysis tools
- Limitations of network log analysis tools
- Packet Capture File Formats
- Packet Capture Tools
- Packet Structure and Headers
- Protocol Dissection
- Stream Reassembly
- Artifact Extraction
- Traffic Filtering and Searching
- Anomaly Detection in Captures
- Correlating Streams and Artifacts
- Rule Syntax and Structure
- Rule Logic and Conditions
- Field Mapping and Data Sources
- Thresholds and Tuning
- Rule Testing and Validation
- Performance Impact
- Rule Lifecycle and Versioning
- Troubleshooting Methodology
- Attack TTP Identification
- TTP Categorization
- TTP Mapping to Frameworks
- TTP Analysis from Evidence
- Threat Modeling Fundamentals
- Threat Modeling Methodologies
- Asset Identification and Classification
- Trust Boundaries and Data Flow Analysis
- Threat Actor Profiling
- Vulnerability and Exploit Analysis
- Risk Assessment and Prioritization
- Mitigation Strategy Development
- Threat Model Documentation and Communication
- Case Investigation Overview
- Evidence Collection and Preservation
- Data Analysis Techniques
- Root Cause Analysis
- Reporting and Documentation
- Sample extraction and identification
- Packet capture and analysis tools
- Reverse engineering fundamentals
- Dynamic malware analysis in sandbox
- Sandbox environment setup and limitations
- Static malware analysis techniques
- Determining need for additional static analysis
- Summarizing and sharing analysis results
- Predictive AI in traffic analysis
- Attack sequence interpretation
- Correlating AI alerts with attack stages
- Distinguishing normal vs. malicious patterns
- Using AI insights for incident response
- Endpoint Investigation Overview
- Evidence Collection and Preservation
- Analysis Techniques for Endpoint Data
- Platform-Specific Investigation Considerations
- Correlation and Contextualization
- Reporting and Remediation
- Definition of IOCs
- Definition of IOAs
- Types of IOCs
- Types of IOAs
- Differences between IOCs and IOAs
- Sources of IOCs and IOAs
- Use of IOCs in detection
- Use of IOAs in detection
- Limitations of IOCs
- Limitations of IOAs
- Correlation of IOCs and IOAs
- Sandbox Environment Fundamentals
- Dynamic Analysis Techniques
- Identifying Indicators of Compromise (IOCs)
- Generating Complex Indicators
- Correlating Sandbox Outputs
- Investigation workflow
- Cloud data loss vectors
- Endpoint data loss vectors
- Server data loss vectors
- Database data loss vectors
- Application data loss vectors
- Evidence collection and preservation
- Correlation and analysis
- Vulnerability Mitigation Overview
- Prioritization of Vulnerabilities
- Patch Management
- Configuration Hardening
- Network Segmentation and Access Control
- Security Controls Implementation
- Monitoring and Detection
- Incident Response and Remediation
- User Awareness and Training
- Continuous Improvement and Review
- CVSS fundamentals
- CVSS vector and scoring calculation
- CVSS limitations and alternatives
- Vulnerability triage process
- Risk analysis techniques
- Recommend next steps
- SOAR definition and purpose
- SOAR vs SIEM vs orchestration
- SOAR platforms
- SOAR mechanisms
- SOAR use cases
- Python script structure
- Variables and data types
- Control flow statements
- Functions and modules
- File I/O operations
- Error handling
- Interpreting script output
- Script Modification Fundamentals
- Understanding Script Inputs and Outputs
- Implementing Security Operations Logic
- Error Handling and Robustness
- Testing and Validation
- JSON structure
- JSON parsing
- HTML structure
- HTML data extraction
- CSV format
- CSV parsing
- XML structure
- XML parsing
- Data format comparison
- SOAR automation opportunities
- SOAR orchestration opportunities
- Machine learning in SOAR
- Assessing automation feasibility
- Workflow design for automation
- Integration and API considerations
- Human-machine teaming
- Rate limiting
- Handling rate limits
- API timeouts
- Handling timeouts
- Payload size and format constraints
- Payload validation and error handling
- API response codes and error messages
- HTTP response code categories
- Common 2xx success codes
- Common 3xx redirection codes
- Common 4xx client error codes
- Common 5xx server error codes
- Mapping HTTP codes to REST API scenarios
- HTTP response structure
- HTTP response status codes
- HTTP response headers
- HTTP response body
- Interpreting HTTP responses in cybersecurity
- Basic authentication
- Custom token authentication
- API keys
- Comparison of authentication mechanisms
- CI/CD pipeline overview
- Version control integration
- Build automation
- Test automation
- Artifact management
- Deployment strategies
- Pipeline orchestration
- Security in CI/CD
- DevOps principles overview
- Continuous Integration (CI)
- Continuous Delivery (CD)
- Continuous Deployment
- Infrastructure as Code (IaC)
- Configuration management
- Version control
- Automated testing
- Pipeline orchestration
- Monitoring and feedback loops
- Collaboration and culture
- Definition of Infrastructure as Code
- Declarative vs. Imperative Approaches
- Idempotency and Desired State
- Version Control and Collaboration
- Configuration Drift and Remediation
- Immutable Infrastructure
- Infrastructure as Code Tools and Workflows
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 350-201, so none is invented.