Cisco CCNA 200-201 CCNACBR Certification Exam

Cisco Certified Network Associate Cybersecurity 200-201

The Cisco CCNA 200-201 CCNACBR certification validates foundational skills in cybersecurity operations, covering security concepts, security monitoring, host-based analysis, network intrusion analysis, and security policies and procedures. Candidates demonstrate knowledge of the CIA triad, access control models, CVSS metrics, SIEM and SOAR platforms, PCAP and Wireshark analysis, endpoint security technologies, and incident response frameworks such as NIST SP 800-61. The exam consists of 100 questions over 120 minutes, with an 80% passing score.

Certification Overview

  • Exam name: CCNA 200-201 CCNACBR
  • Vendor: Cisco
  • Exam code: 200-201
  • Duration: 120 minutes
  • Total questions: 100
  • Passing score: 80%

Who Should Take This Exam?

SOC Analyst, Cybersecurity Analyst, Security Operations Analyst, Incident Response Analyst, Network Security Analyst, Junior Security Engineer, NOC Technician, IT Support Specialist

Prerequisites

No formal prerequisites; basic familiarity with networking fundamentals, TCP/IP, and general security concepts is recommended.

Topics Covered

  • Topics to be announced

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop

CCNA 200-201 CCNACBR Practice Questions

Our question bank contains 755+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

Security Concepts

Which element of the CIA triad is directly violated when an attacker modifies the amount field in a payment record while it is stored in a database?
  • Confidentiality
  • Integrity
  • Availability
  • Non-repudiation
In the CyberOps Associate exam terminology, what is threat hunting?
  • Automatically blocking traffic that matches a known IPS signature
  • Scoring vulnerabilities according to their exploitability
  • A proactive, analyst-driven search for threats that have evaded existing detection controls
  • Reviewing alerts after a SIEM correlation rule has fired
Which term describes a weakness in a system, such as an unpatched service, that could be taken advantage of by a threat actor?
  • Exploit
  • Risk
  • Threat
  • Vulnerability

Security Monitoring

Which network monitoring technology captures Layer 3/4 flow summaries such as source/destination IP, ports, and byte counts without storing full packet payloads?
  • Full packet capture
  • NetFlow
  • Web content filtering
  • Email content filtering
What type of attack aims to make a service unavailable to legitimate users by overwhelming it with traffic from a single source?
  • Man-in-the-middle attack
  • SQL injection
  • Denial of service
  • Cross-site scripting
Which web application attack involves inserting malicious SQL statements into an input field to manipulate a database query?
  • Cross-site scripting
  • SQL injection
  • Command injection
  • Buffer overflow

Host-Based Analysis

Which endpoint technology specifically monitors host-level activity such as process execution and file changes to detect malicious behavior?
  • Host-based intrusion detection
  • Network firewall
  • DNS server
  • Load balancer
In Windows, which built-in tool is commonly used to view running processes and resource usage?
  • Device Manager
  • Task Manager
  • Group Policy Editor
  • Disk Cleanup
On a Linux system, which command lists currently running processes along with their process IDs?
  • grep
  • cron
  • ps
  • chmod

Network Intrusion Analysis

Which source technology would generate an event when a signature-based rule matches malicious traffic on the network?
  • IDS/IPS
  • DHCP server
  • Load balancer
  • NTP server
An alert fires for traffic that is later confirmed to actually be malicious. What classification is this?
  • True negative
  • False positive
  • True positive
  • False negative
A detection system fails to alert on traffic that is later confirmed to have been malicious. What classification is this?
  • False negative
  • Benign
  • True positive
  • False positive

Security Policies and Procedures

Which management process is responsible for maintaining an up-to-date inventory of all hardware and software resources an organization owns?
  • Asset management
  • Patch management
  • Mobile device management
  • Vulnerability management
Which management process focuses specifically on deploying security updates to fix known software flaws?
  • Mobile device management
  • Configuration management
  • Patch management
  • Asset management
According to NIST SP 800-61, which is the first phase of the incident response lifecycle?
  • Post-incident activity
  • Detection and analysis
  • Preparation
  • Containment, eradication, and recovery

Frequently Asked Questions

How many questions are on the exam?

The CCNA 200-201 CCNACBR exam contains 100 questions.

What is the passing score?

You need 80% to pass.

How long is the exam?

You have 120 minutes to complete the exam.

Practice with realistic mock exams to prepare for your Cisco certification.

This platform provides independent practice questions and mock exams. It is not affiliated with, endorsed by, or sponsored by any certification vendor. All trademarks, certification names, and exam codes are the property of their respective owners and are used for identification purposes only.