Cisco · Practice Exam · Associate · CCNA Cybersecurity · Updated for 2026

Cisco 200-201 CCNA Cybersecurity Practice Exam

Cover the full 200-201 blueprint — security monitoring (the heaviest domain), security concepts, host-based analysis, network intrusion analysis, and security policies and procedures — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
Name change: In early 2026 Cisco renamed this certification from CyberOps Associate to CCNA Cybersecurity, aligning it with the CCNA/CCNP naming family. The exam code stays 200-201, but the suffix changed from CBROPS to CCNACBR, and the blueprint is now v1.2 (which adds objectives recognizing the role of AI in security monitoring and analysis). If you held CyberOps Associate, Cisco migrated it to CCNA Cybersecurity automatically — no retesting. Study material labelled v1.1 or earlier misses the AI objectives. Confirm current details on Cisco’s exam page before scheduling.
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

200-201 exam at a glance

Vendor
Cisco
Exam code
200-201 (suffix CCNACBR; formerly CBROPS)
Certification
Cisco Certified CCNA Cybersecurity (formerly Cisco Certified CyberOps Associate)
Level
Associate
Blueprint
v1.2 (Oct 2024 update; adds AI-in-monitoring objectives)
Duration
120 minutes
Questions
Approximately 95–105 (varies by form)
Scoring
Scaled score; Cisco does not publish a fixed public cut score. Confirm on Cisco’s page
Domains
Five, with published weights (see below); they sum to 100%
Prerequisites
None formally required; foundational networking and security knowledge and some hands-on experience are recommended
Cost (USD)
Around $300 (confirm current and regional pricing with Cisco)
Delivery
Pearson VUE; test center or online proctored

Sources: Cisco Learning Network — 200-201 (CCNACBR) exam topics · Cisco — official 200-201 v1.2 exam-topics PDF. Verify current details with Cisco before scheduling.

About the Cisco 200-201 CCNA Cybersecurity certification

The 200-201 exam earns Cisco’s associate-level cybersecurity-operations credential — now called CCNA Cybersecurity after the early-2026 rename from CyberOps Associate. It validates the day-one skills of a Security Operations Center (SOC) analyst: understanding security concepts, monitoring for threats, analyzing hosts and network intrusions, and following incident-response policies and procedures. For how certification exams work generally, see the certification study guides in our Learning Hub.

Because the exam is a step up from Cisco’s entry-level track, the natural feeder is CCST Cybersecurity (100-160). From here, the deeper security path continues to CyberOps Professional-level work such as CBRCOR (350-201). The v1.2 blueprint is a minor update that keeps the domains aligned to current SOC tooling and explicitly recognizes AI’s growing role in monitoring and analysis.

Every PowerKram practice question maps to one of the five weighted domains and links to Cisco’s own exam topics, so a weak spot becomes a specific study step rather than a guess.

200-201 exam domains and weights (v1.2)

Cisco publishes five weighted domains for the 200-201 exam, and they sum to 100%. Security Monitoring is the single heaviest area, and together with Network Intrusion Analysis it makes up nearly half the exam — so weight your study accordingly. Confirm the current weights on Cisco’s exam topics before scheduling.

Security Monitoring

Monitoring technologies and the data they produce (packet capture, session and transaction data, NetFlow), inline vs tap deployment, true/false positive/negative classification, network attack types, and evasion techniques.

25%Heaviest domain
Security Concepts

The CIA triad, defense-in-depth, security deployments (network/endpoint/application, agent vs agentless, SIEM/SOAR), core security terms, and comparing detection approaches (rule-based vs behavioral/statistical).

20%
Host-Based Analysis

Endpoint telemetry and logs, Windows and Linux artifacts an analyst reads, malware-analysis basics, and interpreting the output of sandbox/detonation tools.

20%
Network Intrusion Analysis

Mapping events to source technologies (IDS/IPS, firewall, proxy, NetFlow), packet and protocol analysis, deep packet inspection vs packet filtering, and interpreting network evidence.

20%
Security Policies and Procedures

Incident response and the incident-handling process, common SOC playbooks, the cyber kill chain and related models, and the policies that govern analyst work.

15%

Source: Cisco — official 200-201 v1.2 exam-topics PDF. Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.

Who the 200-201 exam is for

200-201 is aimed at people entering or working in security operations:

  • Aspiring and junior SOC analysts validating threat-monitoring and incident-analysis skills.
  • IT and network staff moving into security who want a recognized associate-level security credential.
  • Help-desk and support technicians stepping up from entry-level security into operations.
  • Students and career-changers targeting a first SOC-analyst role.

The clean feeder is CCST Cybersecurity (100-160) for those newer to security; the associate-level networking sibling is CCNA (200-301); and the deeper security path continues toward CBRCOR (350-201). For where SOC skills lead, see the cybersecurity and SOC-analyst career paths in our Career Hub.

What this 200-201 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam topics each question maps to — immediately after each question. Ideal for the monitoring and intrusion-analysis domains, where data interpretation is the main skill.

Exam mode

Timed, full-length simulation weighted toward Security Monitoring and spanning all five domains at the real 120-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own 200-201 exam topics, so you can verify monitoring, host-analysis, and intrusion concepts against the source.

Score by weighted domain

Results break down across the five weighted domains so you can see whether it’s monitoring, concepts, host analysis, intrusion analysis, or policies that needs more work.

Sample 200-201 practice questions

Ten free questions across the 200-201 weighted domains, with full explanations and source links to Cisco’s exam topics. The complete bank is available with the 24-hour trial.

Question 1 · Security Concepts (20%)

Which pairing correctly matches a security tool category to its primary function?

  1. SIEM collects and correlates log data for detection and analysis
  2. A SIEM physically replaces all firewalls
  3. SOAR is a type of network cable
  4. A SIEM encrypts hard drives
Show answer & explanation

Correct: A. A SIEM (Security Information and Event Management) aggregates and correlates logs and events from across the environment to support detection, alerting, and investigation — a core security-deployment concept.

Why not the others: a SIEM complements rather than replaces firewalls (B), SOAR is an automation/orchestration platform not a cable (C), and a SIEM does not encrypt drives (D).

Source: Cisco — 200-201: security concepts → Further reading: PowerKram — CCST Cybersecurity (100-160) →
Question 2 · Security Monitoring (25%)

A monitoring system flags benign activity as malicious. How is this classified?

  1. True negative
  2. False positive
  3. True positive
  4. False negative
Show answer & explanation

Correct: B — false positive. A false positive is an alert on activity that is actually benign. Tuning to reduce false positives (without creating false negatives) is a core security-monitoring skill.

Why not the others: a true negative (A) correctly ignores benign activity, a true positive (C) correctly flags a real threat, and a false negative (D) misses a real threat.

Source: Cisco — 200-201: security monitoring → Further reading: PowerKram — CBRCOR (350-201) →
Question 3 · Network Intrusion Analysis (20%)

What is the key operational difference between an IDS and an IPS?

  1. An IDS encrypts traffic; an IPS compresses it
  2. They are identical in every way
  3. An IDS detects and alerts on threats; an IPS can also block them inline
  4. An IDS is hardware only; an IPS is software only
Show answer & explanation

Correct: C. An IDS (often in passive/tap mode) detects and alerts on suspicious traffic, while an IPS sits inline and can actively block or drop malicious traffic in real time.

Why not the others: neither encrypts or compresses traffic as their defining role (A), they are not identical (B), and both can be delivered in hardware or software (D).

Source: Cisco — 200-201: network intrusion analysis → Further reading: PowerKram — CCNA (200-301) →
Question 4 · Security Concepts (20%)

Which describes the difference between a vulnerability, a threat, and a risk?

  1. They are three words for the same thing
  2. A vulnerability is a weakness, a threat is something that could exploit it, and risk is the potential for loss if it does
  3. A risk is a type of firewall
  4. A threat is a backup schedule
Show answer & explanation

Correct: B. A vulnerability is a weakness, a threat is an actor or event that could exploit it, and risk combines the likelihood of exploitation with the impact — foundational security terminology.

Why not the others: the terms are distinct, not synonyms (A); a risk is not a firewall (C); and a threat is not a backup schedule (D).

Source: Cisco — 200-201: security terms →
Question 5 · Host-Based Analysis (20%)

During host analysis, what does a file hash (such as SHA-256) primarily let an analyst do?

  1. Speed up the CPU
  2. Change the file’s contents automatically
  3. Uniquely identify a file to check it against threat intelligence
  4. Encrypt the network
Show answer & explanation

Correct: C. A cryptographic hash produces a unique fingerprint of a file, letting an analyst match it against known-good or known-bad lists and threat-intelligence feeds — a staple of host-based analysis.

Why not the others: a hash doesn’t speed the CPU (A), alter file contents (B), or encrypt the network (D).

Source: Cisco — 200-201: host-based analysis → Further reading: PowerKram — CBRCOR (350-201) →
Question 6 · Security Monitoring (25%)

Which data source provides summarized information about network flows (source, destination, ports, bytes) rather than full packet contents?

  1. A screenshot
  2. A word-processing document
  3. A BIOS setting
  4. NetFlow
Show answer & explanation

Correct: D — NetFlow. NetFlow records metadata about conversations (addresses, ports, byte/packet counts) without capturing full payloads — efficient for spotting patterns and anomalies at scale, complementing full packet capture.

Why not the others: a screenshot (A), a document (B), and a BIOS setting (C) are not network flow-data sources.

Source: Cisco — 200-201: monitoring data types →
Question 7 · Security Monitoring (25%)

Which factor most reduces a monitoring tool’s visibility into traffic content?

  1. Larger monitors
  2. Brighter cabling
  3. A slower mouse
  4. Encryption of the traffic
Show answer & explanation

Correct: D. Encryption (along with tunneling, NAT/PAT, and TOR) reduces what a monitoring tool can see inside traffic — a key visibility consideration the exam calls out explicitly.

Why not the others: monitor size (A), cabling (B), and mouse speed (C) have no bearing on traffic visibility.

Source: Cisco — 200-201: data visibility →
Question 8 · Security Policies & Procedures (15%)

Which ordering reflects a common incident-response process?

  1. Preparation; detection and analysis; containment, eradication, and recovery; post-incident activity
  2. Delete all logs, then ignore the incident
  3. Recovery first, preparation never
  4. Only notify the press
Show answer & explanation

Correct: A. A widely taught incident-response lifecycle runs preparation; detection and analysis; containment, eradication, and recovery; then post-incident (lessons-learned) activity — the backbone of SOC playbooks.

Why not the others: deleting logs (B), skipping preparation (C), or only notifying the press (D) all violate sound incident-handling practice.

Source: Cisco — 200-201: policies & incident response → Further reading: PowerKram — CCST Cybersecurity (100-160) →
Question 9 · Host-Based Analysis (20%)

Which artifact is most useful for reconstructing what processes ran on a Windows host during an incident?

  1. The desktop wallpaper
  2. Event and process logs
  3. The screen brightness setting
  4. The mouse pointer speed
Show answer & explanation

Correct: B. Event and process logs (and related OS artifacts) let an analyst reconstruct process execution, logons, and system events — central to host-based analysis on Windows and Linux.

Why not the others: wallpaper (A), brightness (C), and pointer speed (D) carry no investigative value.

Source: Cisco — 200-201: host artifacts & logs →
Question 10 · Network Intrusion Analysis (20%)

What does full packet capture provide that NetFlow does not?

  1. The physical location of the server room
  2. The employee’s salary
  3. The complete contents (payloads) of the captured traffic
  4. The price of the switch
Show answer & explanation

Correct: C. Full packet capture records entire packets including payloads, enabling deep inspection; NetFlow only summarizes flow metadata. The trade-off is storage and privacy versus depth of visibility.

Why not the others: packet capture doesn’t reveal a room location (A), a salary (B), or hardware pricing (D).

Source: Cisco — 200-201: packet capture vs flow data →

Keep going: Learning & Career resources

200-201 is the associate rung of Cisco’s security-operations path — above the CCST entry point and below Professional-level CyberOps. Two PowerKram hubs back this exam.

Deep dive: the 2026 rename, the v1.2 blueprint, and study path

The 2026 rename explained

In early 2026 Cisco renamed CyberOps Associate to CCNA Cybersecurity, aligning it with the CCNA/CCNP family. The exam code stayed 200-201; only the suffix changed (CBROPS to CCNACBR) and the content moved to v1.2. If you held CyberOps Associate, it was migrated automatically with no retest. When a provider, forum, or practice test says “CyberOps Associate,” “CCNACBR,” or “CCNA Cybersecurity,” the anchor to check is the 200-201 code and the v1.2 version. See CCST Cybersecurity (100-160) →

The five weighted domains

Security Monitoring (25%) is the heaviest, and with Network Intrusion Analysis (20%) it decides nearly half your score — these are the day-job skills of a SOC analyst. Security Concepts (20%) and Host-Based Analysis (20%) round out the technical core, and Security Policies and Procedures (15%) covers incident response and playbooks. Weight your revision toward monitoring and intrusion analysis. See CBRCOR (350-201) →

Realistic study path

Learn to read data, not just recall facts: practice interpreting logs, flow records, and packet captures, and classifying alerts as true/false positive/negative. Because v1.2 adds AI-in-monitoring objectives, make sure your materials are current. Finish with objective-mapped practice questions and at least one timed 120-minute run. Confirm the current blueprint and weights on Cisco’s exam topics. See CCNA (200-301) →

Frequently asked questions

Is 200-201 still called CyberOps Associate?
Not anymore. In early 2026 Cisco renamed it to CCNA Cybersecurity, aligning it with the CCNA/CCNP family. The exam code stays 200-201, but the suffix changed from CBROPS to CCNACBR. Existing CyberOps Associate holders were migrated automatically, with no retesting required.
What is different in the v1.2 blueprint?
v1.2 is a minor update that keeps the domains aligned to current SOC tooling and adds objectives recognizing the role of AI in security monitoring and analysis. Study material labelled v1.1 or earlier misses the AI objectives, so make sure your resources target v1.2.
What are the exam domains and weights?
Five weighted domains that sum to 100%: Security Monitoring (25%, heaviest), Security Concepts (20%), Host-Based Analysis (20%), Network Intrusion Analysis (20%), and Security Policies and Procedures (15%). Monitoring and intrusion analysis together make up nearly half the exam.
How long is the exam and what does it cost?
The exam runs 120 minutes with roughly 95–105 questions and a scaled score, and costs around $300 USD (regional pricing varies). Cisco does not publish a fixed public cut score. Confirm current details on Cisco’s exam page.
What should I take before and after 200-201?
A good feeder is CCST Cybersecurity (100-160) for those newer to security. After 200-201, the deeper security path continues toward Professional-level CyberOps work such as CBRCOR (350-201). The associate-level networking sibling is CCNA (200-301).

Start your free 24-hour 200-201 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across Security Monitoring, Security Concepts, Host-Based Analysis, Network Intrusion Analysis, and Security Policies. No credit card required.

Start free trial →