HomeRoadmaps › CCNA Cybersecurity
Active Cisco associate certification

Cisco 200-201 CCNACBR v1.2 Roadmap

Prepare for CCNA Cybersecurity by moving from security principles to source-aware monitoring, host and packet evidence, defensible triage, governed containment, trusted recovery, and measurable lessons learned.

120 minutesPerformance-basedMultiple choiceDrag/drop5 domains
Official scope check: Cisco identifies 200-201 CCNACBR v1.2 as a 120-minute exam leading to CCNA Cybersecurity, with performance-based, multiple-choice, and drag-and-drop formats. Cisco publishes domain weights rather than a fixed live question count. The 50 questions here are an original practice set. Recheck the official exam page and v1.2 topics.

Exact 50-question practice allocation

Security Concepts · 10CIA, risk, access, cryptography, threats, defense in depth, segmentation and zero trust.
Security Monitoring · 13Sources, SIEM, flows, normalization, baselines, intelligence, health, correlation and triage.
Host-Based Analysis · 10Processes, files, hashes, persistence, authentication, volatility, identity and isolation.
Network Intrusion Analysis · 10TCP, DNS, HTTP, TLS metadata, IDS/IPS, ARP, flow/packet evidence and lateral movement.
Policies and Procedures · 7Preparation, classification, custody, handling, communication, containment, recovery and lessons.
1

Security concepts and analytical language

Week 1: build precise terms so triage does not confuse a vulnerability, indicator, alert and incident.

  • Apply confidentiality, integrity and availability to realistic service outcomes.
  • Distinguish threat, vulnerability, exposure, likelihood, impact and risk.
  • Use least privilege, separation of duties, defense in depth and segmentation.
  • Understand authentication, authorization and accounting.
  • Differentiate hashing, encryption, digital signatures and PKI trust.
  • Recognize phishing, social engineering, malware and ransomware behavior.
  • Explain zero trust as explicit verification and continuous least privilege, not a product.
  • Complete all ten Security Concepts questions and related cards.
2

Monitoring architecture, source health and triage

Weeks 2–3: create an evidence pipeline that can state what it sees and when it is blind.

  • Map firewall, DNS, proxy, flow, identity, endpoint, application and email sources.
  • Normalize fields and time while retaining source IDs and raw references.
  • Understand SIEM collection, correlation, prioritization, investigation and reporting.
  • Use NTA for north-south and east-west behavior and flow-level baselines.
  • Apply threat intelligence with source, confidence, age and local context.
  • Track collection, parsing, queue, delivery, detector and synthetic-test health.
  • Separate false positives from false negatives and tune with regression tests.
  • Validate source health before deciding an alert disposition.
3

Host-based evidence and containment

Weeks 4–5: reconstruct execution and persistence while preserving volatile state.

  • Read process ancestry, command lines, users, privileges and execution time.
  • Use file hashes for identity without treating them as proof of maliciousness.
  • Inspect services, scheduled tasks, startup entries and login persistence.
  • Correlate authentication, account changes and service-account purpose.
  • Distinguish volatile memory, processes and sockets from stored evidence.
  • Recognize legitimate-tool abuse through behavior rather than filename alone.
  • Isolate endpoints while preserving approved management and forensic paths.
  • Search peer hosts for both exact indicators and equivalent behavior.
4

Network intrusion analysis

Weeks 6–7: interpret protocols and correlate packet, flow, DNS and endpoint outcomes.

  • Reconstruct TCP handshake, resets, retransmissions and session outcomes.
  • Distinguish scanning from authorized discovery through context and rate.
  • Investigate high-entropy DNS, unusual query volume and resolver behavior.
  • Analyze HTTP request and response evidence without equating attempts with exploitation.
  • Use TLS handshake, certificate, endpoint, timing and volume metadata honestly.
  • Differentiate passive IDS visibility from inline IPS prevention and availability risk.
  • Investigate ARP changes with gateway ownership, CAM and port evidence.
  • Correlate lateral movement with identity, process, protocol, targets and successful outcomes.
5

Policies, response, projects and readiness

Week 8+: turn evidence into authorized decisions, trusted recovery and tested improvement.

  • Define roles, severity, declaration, communication, legal/privacy and technical authority.
  • Preserve hashes, custody, access and retention for evidence.
  • Record observations, hypotheses, confidence, unknowns and decision thresholds.
  • Contain the least capability needed, validate target identity and retain rollback.
  • Recover from trusted state, rotate exposed authority and validate monitoring.
  • Complete all three projects, including loss, wrong-target and recurrence injects.
  • Answer all 50 questions and review all 40 nonduplicate flashcards.
  • Recheck Cisco's active v1.2 topics and current testing policies before scheduling.

Three deep projects

SOC telemetry and triage rangeNormalize network, identity and endpoint evidence; detect a safe chain; tune and respond.
Host and network investigationAnalyze process, persistence, DNS, TCP, peers, evidence, containment and recovery.
Incident tabletopExercise policy, custody, communications, cross-team containment, recovery and lessons.

All learning surfaces

Official Cisco sources

CCNACBR examCisco exam page
CCNACBR v1.2 topicsCisco Learning Network
Cisco security topicsCybersecurity overview

Frequently asked questions

What is the current CCNACBR version and duration?

Cisco lists 200-201 CCNACBR v1.2 as a 120-minute exam. Verify current details before scheduling.

What certification does it earn?

Cisco states that passing the exam earns CCNA Cybersecurity. Refer to the current certification page for recertification and policy details.

Which formats can appear?

Cisco identifies performance-based, multiple-choice, and drag-and-drop formats. These materials use original scenarios and ordering exercises without reconstructing live items.

How are the 50 practice questions allocated?

Security Concepts 10, Security Monitoring 13, Host-Based Analysis 10, Network Intrusion Analysis 10, and Security Policies and Procedures 7.

Is a fixed live question count or passing score claimed?

No. Fifty is only this practice bank's size. Use Cisco's current official exam and delivery information for published logistics.

Are these recalled exam questions?

No. Every question is original educational content based on public objectives and official Cisco documentation.

Independence and integrity: PrepKloud is independent and not affiliated with or endorsed by Cisco. Cisco names and marks belong to Cisco. No exam dumps, recalled questions, fixed live question count, passing score, pass guarantee, attribution claim or production assurance is provided.

Practice evidence-led cyber operations

Complete the questions, cards and three projects while keeping every conclusion bounded by source health and evidence.

Start questionsReview cardsOpen projectsRead guide