Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CISCO

Cisco Certified Network Professional Cybersecurity (CBRCOR)

350-201

The Cisco Certified Network Professional Cybersecurity (CBRCOR) certification validates your expertise in core cybersecurity operations, covering fundamentals, techniques, processes, and automation. It is designed for security professionals who protect networks and data in complex environments. Earning this credential demonstrates your ability to address nuanced security challenges and elevates your career in the growing cybersecurity field.

Exam formatMultiple choice and multiple response
Duration120 minutes
DeliveryPearson VUE
Free questions2075

Content last reviewed 30 July 2026 · Up to date

The certification

What 350-201 proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
58objectives
384concepts
US $400exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Cisco Certified Network Professional Cybersecurity (CBRCOR) certification validates a candidate's advanced knowledge and skills in core cybersecurity operations. This professional-level credential proves your ability to handle nuanced security challenges, from attack prevention to daily threat monitoring, and is a key step for security professionals looking to advance their careers.

Achieving this certification demonstrates your expertise in cybersecurity fundamentals, techniques, processes, and automation. It is a globally recognized credential that signals to employers your capability to design, implement, and manage robust security operations, making you a vital asset in protecting the modern digital landscape.

Who it’s for

This certification is for cybersecurity professionals who are responsible for designing, implementing, and managing security operations. It is ideal for those seeking to validate their skills in core security operations, including threat monitoring, incident response, and security automation. The target audience includes security operations center (SOC) analysts, security engineers, and network security professionals who want to demonstrate their expertise at a professional level and advance their careers in the cybersecurity domain.

Recommended experience

Candidates should have a strong understanding of cybersecurity fundamentals and practical experience in security operations. While not mandatory, hands-on experience with Cisco security technologies is highly recommended. A solid foundation in networking concepts and security principles.; Experience with security operations center (SOC) workflows and incident response.; Familiarity with security automation and orchestration concepts.; Hands-on experience with Cisco security products and solutions.

The syllabus

What you’ll learn

Every domain and objective Cisco measures, with the weight they carry on the exam.

The official Cisco exam outline · checked 30 July 2026 · See the source

Fundamentals
  • 1.1 Interpret the components within a playbook
  • 1.2 Determine the tools needed based on a playbook scenario
  • 1.3 Apply the playbook for a common scenario such as unauthorized elevation of privilege, DoS and DDoS, website defacement
  • 1.4 Infer the industry for various compliance standards such as PCI, FISMA, FedRAMP, SOC, SOX, PCI, GDPR, Data Privacy, and ISO 27101
  • 1.5 Describe the purpose of cyber risk insurance
  • 1.6 Analyze elements of a risk analysis (combination asset, vulnerability, and threat)
  • 1.7 Apply the incident response workflow
  • 1.8 Describe characteristics and areas of improvement using common incident response metrics
  • 1.9 Describe types of cloud environments
  • 1.10 Compare security operations considerations of cloud platforms such as IaaS, PaaS
10 objectives · 373 free questions · 80 pages
Techniques
  • 2.1 Recommend AI-powered data analytic techniques to meet specific needs or answer specific questions
  • 2.2 Describe the use of hardening machine images for deployment
  • 2.3 Describe the process of evaluating the security posture of an asset
  • 2.4 Evaluate the security controls of an environment, diagnose gaps, and recommend improvement
  • 2.5 Determine resources for industry standards and recommendations for hardening of systems
  • 2.6 Determine patching recommendations, given a scenario
  • 2.7 Recommend services to disable, given a scenario
  • 2.8 Apply segmentation to a network
  • 2.9 Utilize network controls for network hardening
  • 2.10 Determine DevSecOps recommendations (implications)
  • 2.11 Describe use and concepts related to using a Threat Intelligence Platform (TIP) to automate intelligence
  • 2.12 Apply AI-driven threat intelligence using tools
  • 2.13 Apply the concepts of data loss, data leakage, data in motion, data in use, and data at rest based on common standards
  • 2.14 Describe the different mechanisms to detect and enforce data loss prevention techniques
  • 2.15 Recommend tuning or adapting devices and software across rules, filters, and policies
  • 2.16 Describe the concepts of security data management
  • 2.17 Describe use and concepts of SIEM tools for security data analytics
  • 2.18 Recommend procedural and SOAR workflows from the described issue through escalation and the automation needed for resolution
  • 2.19 Apply dashboard data to communicate with technical, leadership, or executive stakeholders
  • 2.20 Analyze anomalous user and entity behavior (UEBA) using SIEM data
  • 2.21 Determine the next action based on user behavior alerts
  • 2.22 Describe tools and their limitations for network analysis such as packet capture tools, traffic analysis tools, network log analysis tools
  • 2.23 Evaluate artifacts and streams in a packet capture file
  • 2.24 Troubleshoot existing detection rules
  • 2.25 Determine the tactics, techniques, and procedures (TTPs) from an attack
25 objectives · 995 free questions · 209 pages
Processes
  • 3.1 Analyze components in a threat model
  • 3.2 Determine the steps to investigate the common types of cases
  • 3.3 Apply the concepts and sequence of steps in the malware analysis process
  • 3.4 Interpret the sequence of events during an attack based on predictive AI analysis of traffic patterns
  • 3.5 Determine the steps to investigate potential endpoint intrusion across a variety of platform types such as desktop, laptop, IoT, mobile devices
  • 3.6 Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs)
  • 3.7 Determine IOCs in a sandbox environment (includes generating complex indicators)
  • 3.8 Determine the steps to investigate potential data loss from a variety of vectors of modality such as cloud, endpoint, server, databases, application
  • 3.9 Recommend the general mitigation steps to address vulnerability issues
  • 3.10 Recommend the next steps for vulnerability triage and risk analysis using industry scoring systems such as CVSS and other techniques
10 objectives · 394 free questions · 83 pages
Automation
  • 4.1 Compare concepts, platforms, and mechanisms of SOAR
  • 4.2 Interpret basic scripts such as Python
  • 4.3 Modify a provided script to automate a security operations task
  • 4.4 Recognize common data formats such as JSON, HTML, CSV, XML
  • 4.5 Determine opportunities for automation, orchestration, and machine learning within a SOAR platform
  • 4.6 Determine the constraints when consuming APIs such as rate limited, timeouts, and payload
  • 4.7 Explain the common HTTP response codes associated with REST APIs
  • 4.8 Evaluate the parts of an HTTP response (response code, headers, body)
  • 4.9 Interpret API authentication mechanisms: basic, custom token, and API keys
  • 4.10 Utilize Bash commands (file management, directory navigation, and environmental variables)
  • 4.11 Describe components of a CI/CD pipeline
  • 4.12 Apply the principles of DevOps practices
  • 4.13 Describe the principles of Infrastructure as Code
13 objectives · 313 free questions · 67 pages
On the day

The exam itself

Everything Cisco publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

Exam code350-201
CertificationCisco Certified Network Professional Cybersecurity (CBRCOR)
Exam formatMultiple choice and multiple response
Duration120 minutes
DeliveryPearson VUE
LanguagesEnglish
PricingUS $400
Certification levelProfessional
After you pass

Where this credential goes next

The path Cisco lays out, how the credential is kept, and where to book.

Step-by-step path to Cisco Certified Network Professional Cybersecurity (CBRCOR)

Cisco Certified Network Professional Cybersecurity (CBRCOR) badgeCredential earnedCisco Certified Network Professional Cybersecurity (CBRCOR) Professional level certification
Renewal and maintenance

Cisco certifications are valid for three years. You can recertify by passing another certification exam or by earning Continuing Education (CE) credits. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. Cisco maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by Cisco

Exam registration

Register for the exam through Pearson VUE, Cisco’s authorized testing partner.

Schedule your exam

Visit the official Cisco certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the 350-201 CBRCOR exam relate to the CCNP Cybersecurity certification?

Passing the 350-201 CBRCOR exam earns you the Cisco Certified Specialist – Cybersecurity Core certification and also meets the core exam requirement for the CCNP Cybersecurity certification. To earn the full CCNP Cybersecurity credential, you must also pass one concentration exam.

Do I need to earn a lower-level Cisco certification before taking the 350-201 CBRCOR exam?

No. Cisco does not require any mandatory prerequisites for this exam. While a CCNA-level understanding of networking and security is recommended, it is not a formal requirement.

How do I schedule the 350-201 CBRCOR exam?

You can schedule the exam through the Cisco Certification Tracking System. First, create a Cisco account on cisco.com, then log in to the Certification Tracking System to complete your profile and schedule your exam.

What is the retake policy if I fail the 350-201 CBRCOR exam?

For most Cisco exams, you must wait 5 calendar days, beginning the day after your exam, before retaking the same exam. This policy applies to the 350-201 CBRCOR exam.

Can I use Cisco Learning Credits to pay for the 350-201 CBRCOR exam?

Yes. The exam price is US $400, or you can use Cisco Learning Credits. Cisco customers and learning partners can redeem Cisco Learning Credits for exam vouchers.

What job roles does the CCNP Cybersecurity certification map to?

The CCNP Cybersecurity certification is designed for security professionals who protect networks and data. It is well-suited for roles such as Security Operations Center (SOC) analyst, security engineer, and cybersecurity specialist.

Can I recertify my CCNP Cybersecurity by passing a different Cisco exam?

Yes. You can recertify by passing another certification exam or by earning Continuing Education (CE) credits through eligible activities. This allows you to keep your certification active for another three years.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 2075 questions, free, no account needed.