Cisco CCNA 200-201 CCNACBR Certification Exam
Cisco Certified Network Associate Cybersecurity 200-201
The Cisco CCNA 200-201 CCNACBR certification validates foundational skills in cybersecurity operations, covering security concepts, security monitoring, host-based analysis, network intrusion analysis, and security policies and procedures. Candidates demonstrate knowledge of the CIA triad, access control models, CVSS metrics, SIEM and SOAR platforms, PCAP and Wireshark analysis, endpoint security technologies, and incident response frameworks such as NIST SP 800-61. The exam consists of 100 questions over 120 minutes, with an 80% passing score.
Certification Overview
- Exam name: CCNA 200-201 CCNACBR
- Vendor: Cisco
- Exam code: 200-201
- Duration: 120 minutes
- Total questions: 100
- Passing score: 80%
Who Should Take This Exam?
SOC Analyst, Cybersecurity Analyst, Security Operations Analyst, Incident Response Analyst, Network Security Analyst, Junior Security Engineer, NOC Technician, IT Support Specialist
Prerequisites
No formal prerequisites; basic familiarity with networking fundamentals, TCP/IP, and general security concepts is recommended.
Topics Covered
- Topics to be announced
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- Drag and Drop
CCNA 200-201 CCNACBR Practice Questions
Our question bank contains 755+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Security Concepts
Which element of the CIA triad is directly violated when an attacker modifies the amount field in a payment record while it is stored in a database?
- Confidentiality
- Integrity
- Availability
- Non-repudiation
In the CyberOps Associate exam terminology, what is threat hunting?
- Automatically blocking traffic that matches a known IPS signature
- Scoring vulnerabilities according to their exploitability
- A proactive, analyst-driven search for threats that have evaded existing detection controls
- Reviewing alerts after a SIEM correlation rule has fired
Which term describes a weakness in a system, such as an unpatched service, that could be taken advantage of by a threat actor?
- Exploit
- Risk
- Threat
- Vulnerability
Security Monitoring
Which network monitoring technology captures Layer 3/4 flow summaries such as source/destination IP, ports, and byte counts without storing full packet payloads?
- Full packet capture
- NetFlow
- Web content filtering
- Email content filtering
What type of attack aims to make a service unavailable to legitimate users by overwhelming it with traffic from a single source?
- Man-in-the-middle attack
- SQL injection
- Denial of service
- Cross-site scripting
Which web application attack involves inserting malicious SQL statements into an input field to manipulate a database query?
- Cross-site scripting
- SQL injection
- Command injection
- Buffer overflow
Host-Based Analysis
Which endpoint technology specifically monitors host-level activity such as process execution and file changes to detect malicious behavior?
- Host-based intrusion detection
- Network firewall
- DNS server
- Load balancer
In Windows, which built-in tool is commonly used to view running processes and resource usage?
- Device Manager
- Task Manager
- Group Policy Editor
- Disk Cleanup
On a Linux system, which command lists currently running processes along with their process IDs?
- grep
- cron
- ps
- chmod
Network Intrusion Analysis
Which source technology would generate an event when a signature-based rule matches malicious traffic on the network?
- IDS/IPS
- DHCP server
- Load balancer
- NTP server
An alert fires for traffic that is later confirmed to actually be malicious. What classification is this?
- True negative
- False positive
- True positive
- False negative
A detection system fails to alert on traffic that is later confirmed to have been malicious. What classification is this?
- False negative
- Benign
- True positive
- False positive
Security Policies and Procedures
Which management process is responsible for maintaining an up-to-date inventory of all hardware and software resources an organization owns?
- Asset management
- Patch management
- Mobile device management
- Vulnerability management
Which management process focuses specifically on deploying security updates to fix known software flaws?
- Mobile device management
- Configuration management
- Patch management
- Asset management
According to NIST SP 800-61, which is the first phase of the incident response lifecycle?
- Post-incident activity
- Detection and analysis
- Preparation
- Containment, eradication, and recovery
Frequently Asked Questions
How many questions are on the exam?
The CCNA 200-201 CCNACBR exam contains 100 questions.
What is the passing score?
You need 80% to pass.
How long is the exam?
You have 120 minutes to complete the exam.
Practice with realistic mock exams to prepare for your Cisco certification.