Cisco · Practice Exam · Professional · CyberOps Core · Updated for 2026

Cisco 350-201 CBRCOR Performing CyberOps Practice Exam

Cover the full 350-201 v1.1 blueprint — cybersecurity fundamentals, techniques, processes, and automation for the modern SOC — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

350-201 exam at a glance

Vendor
Cisco
Exam code
350-201 (CBRCOR)
Full name
Performing CyberOps Using Cisco Security Technologies
Level
Professional
Blueprint
v1.1
Duration
120 minutes
Questions
Approximately 90–110 (Cisco does not publish an exact count)
Role in track
CyberOps Professional core exam — pair with one concentration (CBRFIR or CBRTHD) to earn CyberOps Professional
Also earns
Cisco Certified Specialist – Cybersecurity Core
Domains
Four, with published weights (see below); they sum to 100%
Passing score
Scaled score; Cisco does not publish a fixed public cut score
Prerequisites
None formally required; Cisco recommends roughly 3–5 years of SOC/security-operations experience
Delivery
Pearson VUE; test center or online proctored

Sources: Cisco — CBRCOR (350-201) exam page · Cisco — official CBRCOR v1.1 exam topics (PDF). Verify current details with Cisco before scheduling.

About the Cisco 350-201 CBRCOR exam

The 350-201 CBRCOR exam validates core cybersecurity-operations skills for the modern Security Operations Center (SOC) — incident response, threat detection and analysis, security hardening, malware analysis, and automation. It is deliberately broad and tool-agnostic in places while grounded in Cisco security technologies, and it leans on real SOC frameworks and workflows rather than pure product recall. For how certification exams work generally, see the certification study guides in our Learning Hub.

CBRCOR is the core exam of the Cisco CyberOps Professional certification. To earn CyberOps Professional you pass two exams: this core plus one concentration — either CBRFIR (300-215) for forensics and incident response, or CBRTHD (300-220) for threat hunting and defending. Passing CBRCOR on its own also earns the Cisco Certified Specialist – Cybersecurity Core credential. If you’re newer to the field, the associate-level CyberOps Associate (200-201) is the on-ramp below this exam.

Every PowerKram practice question maps to one of the four weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.

350-201 exam domains and weights (v1.1)

Cisco publishes four weighted domains for the 350-201 v1.1 exam, and they sum to 100%. Techniques and Processes tie for the largest share at 30% each — together 60% of the exam — so concentrate on hands-on detection/analysis techniques and investigation processes, then round out fundamentals and automation. Confirm the current weights on Cisco’s exam topics before scheduling.

Fundamentals

Playbooks and the tools they call for; compliance standards (PCI, FISMA, FedRAMP, SOC, SOX, GDPR, ISO 27001); cyber-risk insurance; risk analysis (asset, vulnerability, threat); the incident-response workflow and metrics; and cloud environments and their SecOps considerations.

20%
Techniques

Data-analytic techniques; system and image hardening; posture evaluation and control-gap analysis; patching and segmentation; SecDevOps; Threat Intelligence Platforms; data-loss detection/prevention; tuning detections; UEBA; packet-capture analysis; and deriving TTPs from an attack. One of two largest domains.

30%Largest (tied)
Processes

Threat modeling; investigating common case types; the malware-analysis process (static, dynamic/sandbox, reverse engineering); interpreting attack event sequences; endpoint-intrusion and data-loss investigation; IOCs and IOAs; and vulnerability triage/mitigation using scoring systems like CVSS. One of two largest domains.

30%Largest (tied)
Automation

Orchestration and automation concepts; reading and modifying basic scripts (e.g. Python); data formats (JSON, XML, CSV, HTML); consuming REST APIs (auth, response codes, constraints); Bash basics; and CI/CD, DevOps, and Infrastructure as Code principles.

20%

Source: Cisco — official CBRCOR v1.1 (350-201) exam topics (PDF). Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.

Who the 350-201 exam is for

CBRCOR is aimed at experienced security-operations professionals:

  • SOC analysts and engineers (Tier 2/3) detecting, investigating, and responding to threats.
  • Incident responders applying IR workflows, threat models, and malware-analysis processes.
  • Threat and detection engineers tuning detections, using threat intelligence, and deriving TTPs.
  • Security automation practitioners scripting and orchestrating SOC workflows with Python and APIs.

Choose a concentration to complete CyberOps Professional: CBRFIR (300-215) for forensics and IR, or CBRTHD (300-220) for threat hunting. Newer to security operations? Start at the CyberOps Associate (200-201). For where SOC skills lead, see the cybersecurity career paths in our Career Hub.

What this 350-201 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for process questions where the right next investigative step matters.

Exam mode

Timed, full-length simulation spanning all four domains at the real 120-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own CBRCOR exam material, so you can verify each SOC concept and workflow against the source.

Score by weighted domain

Results break down across the four weighted domains so you can see exactly which cybersecurity-operations area needs more work.

Sample 350-201 practice questions

Ten free questions across the 350-201 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.

Question 1 · Fundamentals (20%)

In SOC operations, what is the primary purpose of a playbook?

  1. To provide a repeatable, predefined set of steps for responding to a specific type of incident
  2. To store user passwords
  3. To replace the firewall
  4. To schedule employee shifts only
Show answer & explanation

Correct: A. A playbook codifies the tools and repeatable steps for handling a specific scenario (e.g. DDoS, privilege escalation, defacement), so response is consistent and fast regardless of who is on shift. Interpreting playbook components is an explicit Fundamentals objective.

Why not the others: playbooks don’t store passwords (B), aren’t a firewall replacement (C), and are about incident response, not shift scheduling (D).

Source: Cisco — CBRCOR: playbooks → Further reading: PowerKram — CBRFIR (300-215) →
Question 2 · Fundamentals (20%)

A payment-card retailer must protect cardholder data. Which compliance standard most directly applies?

  1. GDPR
  2. PCI DSS
  3. FedRAMP
  4. SOX
Show answer & explanation

Correct: B. PCI DSS (Payment Card Industry Data Security Standard) governs the handling of cardholder data. Inferring the right standard for an industry/scenario is a named Fundamentals objective.

Why not the others: GDPR (A) is EU personal-data privacy; FedRAMP (C) governs US federal cloud services; and SOX (D) covers financial reporting controls — none is the card-data standard.

Source: Cisco — CBRCOR: compliance standards →
Question 3 · Techniques (30%)

Which analytic approach flags a user suddenly downloading gigabytes at 3 a.m. when their baseline is a few megabytes during business hours?

  1. Rebooting the workstation
  2. Disabling logging
  3. User and Entity Behavior Analytics (UEBA)
  4. Increasing the MTU
Show answer & explanation

Correct: C. UEBA builds behavioral baselines for users/entities and flags statistically anomalous activity (volume, timing, destinations), catching insider threats and compromised accounts that signature rules miss. Analyzing anomalous behavior is an explicit Techniques objective.

Why not the others: rebooting (A) and raising the MTU (D) don’t detect anomalies, and disabling logging (B) removes the very data UEBA needs.

Source: Cisco — CBRCOR: UEBA → Further reading: PowerKram — CBRTHD (300-220) →
Question 4 · Techniques (30%)

A network is flat and a single compromised host can reach everything. Which technique most directly limits that lateral movement?

  1. Network segmentation
  2. Buying faster switches
  3. Turning off the SIEM
  4. Raising the screen resolution
Show answer & explanation

Correct: A. Segmentation divides the network into zones with controlled paths between them, containing a breach and limiting lateral movement. Applying segmentation and network controls for hardening are named Techniques objectives.

Why not the others: faster switches (B) and higher resolution (D) don’t contain threats, and turning off the SIEM (C) removes visibility.

Source: Cisco — CBRCOR: segmentation & hardening →
Question 5 · Techniques (30%)

Which term describes protecting sensitive information as it moves across the network between systems?

  1. Data at rest
  2. Data in use
  3. Data in motion
  4. Data destruction
Show answer & explanation

Correct: C. Data in motion is data traversing the network (protected primarily with encryption like TLS/IPsec). Distinguishing data at rest, in use, and in motion — and the DLP mechanisms for each — is an explicit Techniques objective.

Why not the others: data at rest (A) is stored data; data in use (B) is data being processed in memory; and “data destruction” (D) is disposal, not a transit state.

Source: Cisco — CBRCOR: data states & DLP →
Question 6 · Processes (30%)

An analyst runs suspected malware in an isolated instrumented environment to watch its behavior. Which malware-analysis method is this?

  1. Static analysis
  2. Dynamic analysis in a sandbox
  3. Physical destruction
  4. Ignoring the sample
Show answer & explanation

Correct: B. Dynamic analysis executes the sample in a sandbox to observe runtime behavior (files, registry, network) and generate indicators. Static analysis, by contrast, inspects the file without running it. The exam expects the full sequence: extract → reverse engineer → dynamic → static → share.

Why not the others: static analysis (A) doesn’t execute the sample; physical destruction (C) and ignoring it (D) aren’t analysis at all.

Source: Cisco — CBRCOR: malware analysis process →
Question 7 · Processes (30%)

A specific malicious file hash and a known-bad C2 IP are observed on a host. In investigation terms, these are best described as what?

  1. Marketing metrics
  2. Firewall license keys
  3. Screen resolutions
  4. Indicators of Compromise (IOCs)
Show answer & explanation

Correct: D. IOCs are forensic artifacts (file hashes, malicious IPs/domains, registry keys) indicating a compromise has occurred. They differ from IOAs, which focus on attacker behavior/intent. Determining IOCs (and IOAs) is a named Processes objective.

Why not the others: marketing metrics (A), license keys (B), and screen resolutions (C) are not investigative indicators.

Source: Cisco — CBRCOR: IOCs & IOAs → Further reading: PowerKram — CBRFIR (300-215) →
Question 8 · Processes (30%)

To prioritize which of many vulnerabilities to remediate first, which industry scoring system does the exam expect you to apply?

  1. Body Mass Index
  2. A credit score
  3. The Common Vulnerability Scoring System (CVSS)
  4. A Wi-Fi signal bar count
Show answer & explanation

Correct: C. CVSS produces a standardized severity score (0–10) from exploitability and impact metrics, giving a defensible basis for triage. Recommending next steps for vulnerability triage using CVSS is an explicit Processes objective.

Why not the others: BMI (A), a credit score (B), and Wi-Fi bars (D) have nothing to do with vulnerability severity.

Source: Cisco — CBRCOR: vulnerability triage (CVSS) →
Question 9 · Automation (20%)

A SOAR workflow calls a REST API and receives HTTP 429. What does that most likely indicate?

  1. Success with no content
  2. The server permanently moved
  3. Authentication succeeded
  4. The request was rate-limited (too many requests)
Show answer & explanation

Correct: D. HTTP 429 “Too Many Requests” signals rate limiting; a robust automation should back off and retry. Understanding REST response codes and API constraints (rate limits, timeouts, payloads) is a named Automation objective.

Why not the others: 204 is success-no-content (A), 301 is a permanent move (B), and a 2xx would indicate success (C) — none is 429.

Source: Cisco — CBRCOR: REST APIs & response codes → Further reading: PowerKram — CyberOps Associate (200-201) →
Question 10 · Automation (20%)

Which data format — lightweight, key/value, and human-readable — is most commonly returned by modern security REST APIs?

  1. A JPEG image
  2. JSON (JavaScript Object Notation)
  3. An MP3 file
  4. A physical punch card
Show answer & explanation

Correct: B. JSON is the lightweight, human-readable key/value format most REST APIs use for request/response bodies; parsing it is fundamental to SOC automation. Recognizing common data formats (JSON, XML, CSV, HTML) is a named Automation objective.

Why not the others: a JPEG (A) and MP3 (C) are binary media, and a punch card (D) is obsolete physical media — none is an API data-interchange format.

Source: Cisco — CBRCOR: data formats →

Keep going: Learning & Career resources

CBRCOR is the core of the CyberOps Professional track. Two PowerKram hubs back this exam.

Deep dive: the CyberOps Professional track and study strategy

What CBRCOR covers

CBRCOR is a SOC-operations exam: it tests how you detect, analyze, investigate, and respond to threats, and how you automate that work. The four domains mirror the SOC lifecycle — Fundamentals (playbooks, compliance, risk, IR workflow), Techniques (hardening, detection, threat intel, UEBA, packet analysis), Processes (threat modeling, malware analysis, IOCs/IOAs, CVSS triage), and Automation (scripting, APIs, CI/CD). Techniques and Processes each carry 30%, so the hands-on analytical work is where most of the exam lives. See CBRFIR (300-215) →

How CBRCOR fits CyberOps Professional

CyberOps Professional requires two exams: this core plus one concentration — CBRFIR (300-215) for forensics and incident response, or CBRTHD (300-220) for threat hunting and defending. Passing CBRCOR alone also earns Cisco Certified Specialist – Cybersecurity Core. The associate-level CyberOps Associate (200-201) is the entry tier below. See CBRTHD (300-220) →

Realistic study path

Cisco recommends several years of SOC experience for this exam, and it shows in the scenario framing. Spend the most time on Techniques and Processes: practice reading packet captures, tuning detections, running the malware-analysis sequence, distinguishing IOCs from IOAs, and triaging with CVSS. Don’t skip Automation — be comfortable reading a short Python script, interpreting HTTP response codes, and parsing JSON. The exam runs 120 minutes, longer than most concentration exams, so build stamina with a full timed simulation. See CyberOps Associate (200-201) →

Frequently asked questions

What is the 350-201 CBRCOR exam?
350-201 CBRCOR is “Performing CyberOps Using Cisco Security Technologies,” the core exam of the Cisco CyberOps Professional certification. It tests core cybersecurity-operations skills — fundamentals, techniques, processes, and automation — for working in a modern Security Operations Center.
How do I earn CyberOps Professional?
You pass two exams: the 350-201 CBRCOR core plus one concentration — either 300-215 CBRFIR (forensics and incident response) or 300-220 CBRTHD (threat hunting and defending). Passing CBRCOR on its own also earns the Cisco Certified Specialist – Cybersecurity Core credential.
How long is the exam and how many questions?
CBRCOR runs 120 minutes with roughly 90–110 questions (Cisco does not publish an exact count). It uses a scaled score, and Cisco does not publish a fixed public cut score. Confirm current details on Cisco’s exam page before scheduling.
What are the exam domains and weights?
Four weighted domains (v1.1) that sum to 100%: Fundamentals (20%), Techniques (30%), Processes (30%), and Automation (20%). Techniques and Processes tie for the largest at 30% each.
Do I need experience or the CyberOps Associate first?
There are no formal prerequisites, but Cisco recommends roughly three to five years of security-operations experience. If you’re newer to the field, the associate-level CyberOps Associate (200-201) is a sensible on-ramp before attempting CBRCOR.

Start your free 24-hour 350-201 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all four CBRCOR domains. No credit card required.

Start free trial →