Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Cisco
Exam Format
120 min
95-105
825
Associate
Registration
$300 USD
Pearson VUE or online proctoring
English
Validity
3 years
Pass current exam before expiration; Pass any Expert-level Cisco exam; Pass two Professional concentration exams
Exam Guide
200-201 Exam Topics and Domains
200-201 is organized into 5 weighted domains.
1
Security Concepts
20%
Describe the CIA triad
- Confidentiality - ensuring data privacy and access control
- Integrity - maintaining data accuracy and trustworthiness
- Availability - ensuring systems and data are accessible when needed
- Identify which pillar of CIA triad is violated in scenarios
- Understand relationship between CIA principles
- Apply CIA triad to real-world security incidents
Compare security deployments
Network, endpoint, and application security systemsAgentless and agent-based protectionsLegacy antivirus and antimalwareSIEM, SOAR, and log managementContainer and virtual environmentsCloud security deployments
- Compare and contrast different security deployment models
- Identify appropriate security technologies for various scenarios
- Understand the evolution from legacy to modern security solutions
Describe security terms
Threat intelligence (TI)Threat huntingMalware analysisThreat actorRun book automation (RBA)Reverse engineeringSliding window anomaly detectionThreat modelingDevSecOps
- Define and explain modern cybersecurity terminology
- Understand the role of each security practice in overall security posture
Compare security concepts
RiskThreatVulnerabilityExploit
- Distinguish between risk, threat, vulnerability, and exploit
- Calculate or assess risk in given scenarios
- Identify relationship between these concepts
Describe the principles of the defense-in-depth strategy
- Layered security approach
- Multiple security controls at different levels
- Network segmentation
- Perimeter security
- Internal security controls
- Endpoint protection
- Data security
- Redundancy and resilience
- Identify layers in defense-in-depth model
- Apply defense-in-depth principles to network design
- Understand why multiple layers are necessary
Compare access control models
Discretionary access control (DAC)Mandatory access control (MAC)Nondiscretionary access controlAuthentication, authorization, accounting (AAA)Rule-based access controlTime-based access controlRole-based access control (RBAC)Attribute-based access control (ABAC)
- Compare and contrast different access control models
- Identify appropriate model for given scenarios
- Understand AAA framework components
Describe terms as defined in CVSS
Attack vectorAttack complexityPrivileges requiredUser interactionScopeTemporal metricsEnvironmental metrics
- CVSS v3.x scoring system (0.0 to 10.0)
- Base metrics: inherent characteristics of vulnerability
- Impact metrics: Confidentiality, Integrity, Availability
- Severity ratings: None (0), Low (0.1-3.9), Medium (4.0-6.9), High (7.0-8.9), Critical (9.0-10.0)
- Calculate or interpret CVSS scores
- Understand impact of each metric on overall score
- Identify appropriate CVSS values for given vulnerabilities
Identify the challenges of data visibility (network, host, and cloud) in detection
- Network visibility challenges: encrypted traffic, high bandwidth, east-west traffic
- Host visibility challenges: endpoint diversity, remote workers, BYOD
- Cloud visibility challenges: multi-tenancy, shared responsibility, API-driven infrastructure
- Encryption impact on inspection
- Distributed infrastructure complexity
- Shadow IT and unauthorized applications
- Identify visibility gaps in security monitoring
- Understand impact of encryption on detection capabilities
- Recognize cloud-specific visibility challenges
Identify potential data loss from traffic profiles
- Unusual outbound traffic patterns
- Large data transfers to external destinations
- Access to sensitive file repositories
- Use of unapproved cloud storage services
- DNS tunneling and data exfiltration techniques
- Baseline vs anomalous behavior
- Analyze traffic patterns for potential data exfiltration
- Identify indicators of data loss in network flows
- Recognize covert data exfiltration methods
Interpret the 5-tuple approach to isolate a compromised host in a grouped set of logs
- 5-tuple components: source IP, destination IP, source port, destination port, protocol
- Correlation of network sessions
- Isolating malicious traffic patterns
- NetFlow and session analysis
- Identifying compromised endpoints through connection patterns
- Use 5-tuple to trace malicious activity
- Identify compromised hosts from log analysis
- Correlate events across multiple log sources
Compare rule-based detection vs. behavioral and statistical detection
- Rule-based (signature-based): matches known patterns, low false positives, misses unknown threats
- Behavioral detection: analyzes deviations from normal behavior, detects unknown threats, higher false positives
- Statistical detection: uses statistical models and machine learning, adaptive to new patterns
- Hybrid approaches combining multiple detection methods
- Compare advantages and disadvantages of each detection method
- Identify appropriate detection method for scenarios
- Understand limitations of signature-based approaches
2
Security Monitoring
25%
Compare attack surface and vulnerability
- Attack surface: all possible entry points for attacks (network services, applications, APIs, users)
- Vulnerability: specific weakness that can be exploited
- Attack surface reduction techniques
- Relationship between large attack surface and increased vulnerabilities
- Distinguish between attack surface and vulnerability
- Identify methods to reduce attack surface
- Understand how attack surface relates to security posture
Identify the types of data provided by these technologies
TCP dumpNetFlowNext-gen firewall (NGFW)Traditional stateful firewallApplication visibility and control (AVC)Web content filteringEmail content filtering
- Match technology to data type provided
- Understand granularity of data from each source
- Identify appropriate technology for specific monitoring needs
Describe the impact of these technologies on data visibility
Access control list (ACL)NAT/PATTunnelingTOR (The Onion Router)EncryptionP2P (Peer-to-Peer)EncapsulationLoad balancing
- Identify how each technology reduces visibility
- Recognize mitigation strategies for visibility challenges
- Understand trade-offs between security and visibility
Describe the uses of these data types in security monitoring
Full packet captureSession dataTransaction dataStatistical dataMetadataAlert data
- Match data type to appropriate security use case
- Understand trade-offs between data granularity and volume
- Identify which data type would reveal specific threats
Describe network attacks
- Protocol-based attacks: SYN flood, TCP RST, ARP spoofing, DNS amplification
- Denial of Service (DoS): overwhelming single source attack
- Distributed Denial of Service (DDoS): coordinated multi-source attack, botnet-driven
- Man-in-the-Middle (MitM): ARP spoofing, DNS poisoning, SSL stripping, session hijacking
- Amplification attacks: DNS, NTP, SNMP reflection
- Layer 3/4 vs Layer 7 DDoS attacks
- Identify attack types from traffic patterns
- Understand characteristics of DoS vs DDoS
- Recognize MitM attack indicators
- Differentiate protocol-based attacks
Describe web application attacks
- SQL injection: manipulating database queries through user input
- Command injection: executing OS commands through vulnerable inputs
- Cross-Site Scripting (XSS): reflected, stored, DOM-based
- OWASP Top 10 vulnerabilities
- Input validation failures
- Authentication and session management flaws
- Identify SQL injection patterns in logs
- Recognize XSS attack vectors
- Understand command injection techniques
- Differentiate between injection attack types
Describe social engineering attacks
- Phishing: email-based credential theft
- Spear phishing: targeted phishing campaigns
- Whaling: targeting executives/high-value individuals
- Vishing: voice/phone-based social engineering
- Smishing: SMS-based phishing
- Pretexting: creating false scenarios
- Baiting: offering something enticing
- Tailgating/Piggybacking: physical access following
- Watering hole attacks: compromising frequently visited sites
- Identify social engineering techniques in scenarios
- Recognize phishing indicators in emails
- Understand psychological manipulation tactics
- Differentiate between social engineering types
Describe endpoint-based attacks
- Buffer overflows: stack and heap overflows, return-oriented programming (ROP)
- Command and Control (C2): beaconing, HTTP/HTTPS C2, DNS tunneling, covert channels
- Malware types: viruses, worms, trojans, rootkits, keyloggers, spyware
- Ransomware: encryption-based extortion, CryptoLocker, WannaCry, REvil
- Privilege escalation techniques
- Persistence mechanisms: registry keys, scheduled tasks, services
- Identify C2 traffic patterns
- Recognize ransomware indicators
- Understand buffer overflow exploitation
- Differentiate malware types by behavior
Describe evasion and obfuscation techniques
- Tunneling: HTTP tunneling, DNS tunneling, ICMP tunneling for data exfiltration
- Encryption: hiding malicious payloads and C2 communications
- Proxies: anonymizing traffic sources, hiding true destinations
- Polymorphic and metamorphic malware
- Code obfuscation: packing, encryption, anti-debugging
- Steganography: hiding data in images, videos, audio
- Living off the land (LOLBins): using legitimate tools for malicious purposes
- Anti-forensics techniques
- Identify evasion techniques in network traffic
- Recognize obfuscation methods in malware
- Understand how attackers bypass detection
- Identify covert channels and tunneling
Describe the impact of certificates on security
- PKI (Public Key Infrastructure): CA hierarchy, certificate chains, trust models
- Public/private key cryptography: asymmetric encryption, key exchange
- Symmetric encryption: faster but requires shared key
- TLS/SSL handshake process
- Certificate validation: chain of trust, revocation checking (CRL, OCSP)
- Certificate pinning
- Self-signed vs CA-signed certificates
- Understand PKI components and relationships
- Identify certificate validation failures
- Recognize symmetric vs asymmetric encryption use cases
- Understand certificate's role in securing communications
Identify the certificate components in a given scenario
Cipher-suiteX.509 certificatesKey exchangeProtocol versionPKCS (Public Key Cryptography Standards)
- Identify cipher suite components from logs
- Parse X.509 certificate fields
- Recognize secure vs insecure protocol versions
- Understand key exchange methods and their security implications
3
Host-Based Analysis
20%
Describe the functionality of these endpoint technologies in regard to security monitoring utilizing rules, signatures and predictive AI
Host-based intrusion detection (HIDS)Antimalware and antivirusHost-based firewall
- Identify appropriate endpoint technology for monitoring scenarios
- Understand how AI enhances traditional signature-based detection
- Recognize capabilities and limitations of each technology
- Differentiate between rules, signatures, and AI-based detection
Identify components of an operating system (such as Windows and Linux) in a given scenario
- Windows components: Registry, Event Logs, Services, Processes, DLLs, Scheduled Tasks, WMI
- Linux components: /etc files (passwd, shadow, hosts), /var/log, cron jobs, daemons, init/systemd
- File systems: NTFS (Windows), ext4/XFS (Linux)
- User authentication: SAM (Windows), /etc/passwd and /etc/shadow (Linux)
- Process structures: Windows Task Manager, Linux ps/top
- Boot processes: Windows Boot Manager, Linux GRUB
- System logs: Windows Event Viewer, Linux syslog/journald
- Identify OS components in logs and system outputs
- Recognize Windows vs Linux system artifacts
- Understand where to find specific system information
- Locate evidence of malicious activity in OS components
Describe the role of attribution in an investigation
AssetsThreat actorIndicators of compromise (IOCs)Indicators of attack (IOAs)Chain of custody
- Understand the purpose of attribution in investigations
- Distinguish between IOCs and IOAs
- Recognize components of proper chain of custody
- Identify asset classification importance in incident response
Identify type of evidence used based on provided logs
Best evidenceCorroborative evidenceIndirect evidence
- Classify evidence types from log examples
- Understand evidentiary value hierarchy
- Recognize when evidence is direct vs indirect
- Identify corroborative relationships between evidence sources
Compare tampered and untampered disk image
- Hash values: MD5, SHA-1, SHA-256 for integrity verification
- Write blockers: hardware and software to prevent modification
- Forensic imaging tools: dd, FTK Imager, EnCase
- Verification process: hash before imaging, hash after imaging, compare hashes
- Tamper detection: hash mismatch indicates modification
- Timestamp analysis: MACB times (Modified, Accessed, Changed, Birth)
- File system integrity checking
- Identify tampered disk images through hash comparison
- Understand importance of write blockers
- Recognize proper forensic imaging procedures
- Interpret hash verification results
Interpret operating system, application, or command line logs to identify an event
- Windows Event IDs: 4624 (successful logon), 4625 (failed logon), 4648 (explicit credentials), 4688 (process creation), 4672 (special privileges), 4720 (user created)
- Linux syslog priorities and facilities
- Authentication logs: successful/failed login attempts, privilege escalation
- Application logs: errors, crashes, configuration changes
- Command line logging: PowerShell script block logging, bash history
- Process creation events and parent-child relationships
- Network connection logs
- Interpret Windows Event IDs for security events
- Identify malicious activity from command line logs
- Recognize successful vs failed authentication attempts
- Trace process execution through logs
- Correlate events across different log sources
Interpret the output report of a malware analysis tool such as a detonation chamber or sandbox
HashesURLsSystems, events, and networking
- Interpret sandbox reports for malware behavior
- Identify C2 infrastructure from sandbox output
- Recognize malware capabilities from behavioral analysis
- Extract IOCs from sandbox reports (hashes, URLs, IPs)
- Understand malware persistence and evasion techniques from reports
4
Network Intrusion Analysis
20%
Map the provided events to source technologies
IDS/IPSFirewallNetwork application controlProxy logsAntivirusTransaction data (NetFlow)
- Match event format to originating technology
- Identify characteristic fields for each technology
- Recognize log format differences between technologies
Compare impact and no impact for these items
False positiveFalse negativeTrue positiveTrue negativeBenign
- Classify alerts as true/false positives/negatives
- Understand impact of each classification
- Identify benign vs malicious activity
- Recognize trade-offs in detection sensitivity
Compare deep packet inspection with packet filtering and stateful firewall operation
- Packet filtering: Layer 3-4, source/dest IP/port, stateless, fast but limited
- Stateful firewall: tracks connection state, session tables, Layer 3-4, context-aware
- Deep Packet Inspection (DPI): Layer 7, application-level analysis, payload inspection, signature matching, protocol decoding
- Performance trade-offs: packet filtering fastest, DPI slowest but most thorough
- Use cases: packet filtering for basic ACLs, stateful for connection tracking, DPI for malware/content inspection
- Differentiate capabilities of each inspection method
- Understand performance vs security trade-offs
- Identify appropriate method for security requirements
- Recognize limitations of each approach
Compare inline traffic interrogation and taps or traffic monitoring
- Inline interrogation: active inspection, can block traffic, introduces latency, IPS mode, single point of failure risk
- Traffic taps/monitoring: passive observation, cannot block, no latency impact, IDS mode, out-of-band analysis, no traffic disruption
- SPAN/mirror ports: switch-based copies of traffic
- Network TAPs: physical devices for traffic duplication
- Use cases: inline for prevention, taps for detection and forensics
- Compare inline vs passive monitoring characteristics
- Understand when to use each approach
- Identify trade-offs between prevention and detection
- Recognize impact on network operations
Compare the characteristics of data obtained from taps or traffic monitoring and transactional data (NetFlow) in the analysis of network traffic
- Taps/full packet capture: complete packet contents, all layers, high storage requirements, detailed forensics, protocol analysis
- NetFlow/transactional data: flow metadata only, 5-tuple + volume, minimal storage, scalability, trending and baselining
- Granularity: PCAP provides detail, NetFlow provides overview
- Use cases: PCAP for deep dive investigations, NetFlow for broad visibility and anomaly detection
- Understand data richness vs scalability trade-offs
- Identify appropriate data source for analysis tasks
- Recognize limitations of each data type
- Match use case to data collection method
Extract files from a TCP stream when given a PCAP file and Wireshark
- Wireshark Follow TCP Stream feature
- File > Export Objects > HTTP/SMB/etc.
- Reassembling fragmented packets
- Identifying file transfers in traffic
- Extracting malware samples from PCAP
- Handling encoded/compressed data
- File hash calculation for extracted files
- Understand Wireshark file extraction features
- Identify file transfer protocols in PCAP
- Recognize when file extraction is possible
- Understand PCAP analysis workflow
Identify key elements in an intrusion from a given PCAP file
Source addressDestination addressSource portDestination portProtocolsPayloads
- Identify 5-tuple elements in PCAP
- Recognize malicious payload patterns
- Understand protocol usage in attacks
- Correlate packet elements to reconstruct attack flow
Interpret the fields in protocol headers as related to intrusion analysis
Ethernet frameIPv4IPv6TCPUDPICMPDNSSMTP/POP3/IMAPHTTP/HTTPS/HTTP2ARP
- Interpret protocol header fields from packet captures
- Identify normal vs anomalous protocol behavior
- Recognize attack patterns in protocol headers
- Understand protocol field significance in intrusion detection
Interpret common artifact elements from an event to identify an alert
IP address (source / destination)Client and server port identityProcess (file or registry)System (API calls)HashesURI / URL
- Extract key artifacts from alert data
- Correlate artifacts for incident identification
- Recognize IOCs in artifact elements
- Understand artifact significance in investigations
Interpret basic regular expressions
- Character classes: [a-z], [0-9], [A-Za-z0-9]
- Quantifiers: * (0 or more), + (1 or more), ? (0 or 1), {n} (exactly n), {n,m} (between n and m)
- Anchors: ^ (start of line), $ (end of line)
- Metacharacters: . (any character), \ (escape)
- Alternation: | (OR)
- Grouping: ( )
- Common patterns for security: IP addresses, email addresses, URLs, file paths
- Interpret regex patterns for security rules
- Understand what strings will match given regex
- Recognize common regex patterns in IDS rules
- Apply regex for log parsing and searching
5
Security Policies and Procedures
15%
Describe management concepts
Asset managementConfiguration managementMobile device management (MDM)Patch managementVulnerability management
- Understand purpose of each management concept
- Identify appropriate processes for scenarios
- Recognize relationships between management disciplines
- Apply management concepts to security operations
Describe the elements in an incident response plan as stated in NIST.SP800-61
- NIST SP 800-61 Rev 2: Computer Security Incident Handling Guide
- IR plan components: policy, procedures, communication plans, contact information
- Roles and responsibilities: IR team, management, legal, HR, communications
- Incident classification and prioritization
- Escalation procedures
- Documentation requirements
- Tools and resources for IR
- Training and awareness programs
- Identify elements of comprehensive IR plan
- Understand NIST SP 800-61 framework
- Recognize IR team roles and responsibilities
- Apply IR plan elements to scenarios
Apply the incident handling process such as NIST.SP800-61 to an event
- Preparation: IR capabilities, tools, training, playbooks
- Detection and Analysis: monitoring, triage, severity assessment, scoping
- Containment: short-term and long-term strategies, evidence preservation
- Eradication: remove threat actors, malware, close vulnerabilities
- Recovery: restore systems, verify clean state, monitor for re-infection
- Post-Incident Activity: lessons learned, improvements, reporting
- Map incident handling steps to event scenarios
- Identify appropriate actions for each phase
- Understand sequence and dependencies in IR process
- Apply NIST framework to real-world incidents
Map elements to these steps of analysis based on the NIST.SP800-61
PreparationDetection and analysisContainment, eradication, and recoveryPost-incident analysis (lessons learned)
- Classify incident response activities by NIST phase
- Identify which phase contains specific actions
- Understand element placement in IR lifecycle
- Match tasks to appropriate IR stages
Map the organization stakeholders against the NIST IR categories (CMMC, NIST.SP800-61)
PreparationDetection and analysisContainment, eradication, and recoveryPost-incident analysis (lessons learned)
- Identify appropriate stakeholders for each IR phase
- Understand stakeholder roles in incident response
- Map organizational functions to IR categories
- Recognize communication requirements per phase
Describe concepts as documented in NIST.SP800-86
Evidence collection orderData integrityData preservationVolatile data collection
- Understand order of volatility in evidence collection
- Identify proper data preservation techniques
- Recognize volatile vs non-volatile data
- Apply NIST SP 800-86 principles to scenarios
Identify these elements used for network profiling
Total throughputSession durationPorts usedCritical asset address space
- Identify network profiling elements from data
- Understand how profiling supports anomaly detection
- Recognize deviations from baseline profiles
- Apply profiling concepts to threat detection
Identify these elements used for server profiling
Listening portsLogged in users/service accountsRunning processesRunning tasksApplications
- Identify server profiling elements from system data
- Recognize deviations from server baselines
- Understand how profiling detects compromises
- Apply server profiling to incident detection
Identify protected data in a network
PII (Personally Identifiable Information)PSI (Payment Security Information) / PCIPHI (Protected Health Information)Intellectual property
- Classify data types in network traffic
- Identify regulatory requirements for data protection
- Recognize data exfiltration risks by data type
- Understand DLP policy requirements
Classify intrusion events into categories as defined by security models, such as Cyber Kill Chain Model and Diamond Model of Intrusion
- Cyber Kill Chain (Lockheed Martin): Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives
- Diamond Model: Adversary, Capability, Infrastructure, Victim (relationships between elements)
- MITRE ATT&CK: Tactics, Techniques, and Procedures framework
- Using models for incident classification and analysis
- Mapping observed activity to kill chain stages
- Identifying attack progression
- Map incident events to kill chain stages
- Apply Diamond Model to intrusion analysis
- Classify activities by attack framework
- Understand model purpose and application
- Identify defensive actions for each kill chain stage
Describe the relationship of SOC metrics to scope analysis
- Time to Detect (TTD): duration from compromise to detection
- Time to Contain (TTC): duration from detection to containment
- Time to Respond (TTR): duration from detection to initial response
- Time to Control (TTC): duration to fully remediate and restore
- MTTD (Mean Time To Detect): average time to detect incidents
- MTTR (Mean Time To Respond/Recover): average time to respond/recover
- Scope analysis: understanding extent of compromise (systems, data, users affected)
- Metrics inform resource allocation and process improvements
- Relationship: faster metrics generally indicate smaller scope
- Understand SOC metrics definitions
- Recognize how metrics relate to incident scope
- Identify impact of metric improvements
- Apply metrics to incident assessment
How do I earn this certification?
Passing 200-201 earns the Cisco Certified Cybersecurity Associate certification. It sits in the Cybersecurity track.
Next Level Options
- 350-201 - CBRCOR - Performing CyberOps Using Cisco Security TechnologiesCore exam for Cybersecurity Professional certification
- 300-215 - CBRFIR - Conducting Forensic Analysis and Incident Response Using Cisco TechnologiesSpecialist certification in forensics and incident response
- 300-220 - CBRTHD - Cisco Cybersecurity Threat Hunting and Defending Specialist certification in threat hunting
Alternative Paths
- 200-301 - CCNAFoundation networking knowledge complementary to cybersecurity
- 200-901 - DEVASC - DevNet AssociateAutomation and programming skills for security operations
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for 200-201.
What's changed on this exam?
Current Status
- ACTIVE
- Last content update: 2024-10-01
Updates
- AI in Endpoint Security Newly added in v1.2 New topics in Domain 3 (Host-Based Analysis) covering predictive AI and behavioral detection • Release date: 2024-10-01
- NIST Cybersecurity Framework CSF 2.0 Domain 5 references NIST frameworks; CSF 2.0 may appear in future exam updates • Release date: 2024-02-26
- Wireshark 4.x series Critical tool for Domain 4 (Network Intrusion Analysis); latest version recommended for practice • Release date: Ongoing
Who should take this exam?
- 1+ year of cybersecurity or SOC experience
- Basic understanding of networking fundamentals
- Familiarity with Windows and Linux operating systems
- Knowledge of security concepts and terminology