- Exam Overview: What 200-201 CCNACBR Actually Tests
- Domain 1: Security Concepts (20%)
- Domain 2: Security Monitoring (25%)
- Domain 3: Host-Based Analysis (20%)
- Domain 4: Network Intrusion Analysis (20%)
- Domain 5: Security Policies and Procedures (15%)
- How to Sequence Your Study Across All Five Domains
- Who Hires for This Certification
- FAQ
- Security Monitoring is the largest domain at 25% and now includes generative-AI social engineering topics.
- The 200-201 CCNACBR exam has five domains: 20%, 25%, 20%, 20%, and 15%.
- The v1.2 blueprint, effective January 21, 2025, is the version you must study against today.
- No domain can be skipped - even the smallest, Security Policies and Procedures at 15%, appears throughout the 120-minute exam.
Exam Overview: What 200-201 CCNACBR Actually Tests
The Cisco Certified Network Associate Cybersecurity credential is validated through a single computer-delivered exam: 200-201 CCNACBR, "Understanding Cisco Cybersecurity Operations Fundamentals," version 1.2. It runs 120 minutes, is delivered in English through Pearson VUE at an authorized test center or via OnVUE online proctoring, and costs USD 300. There are no formal prerequisites or required training, so your preparation plan should be built entirely around the five content domains rather than around eligibility hoops.
Cisco updated the exam acronym and credential name from Cybersecurity Associate/CBROPS to CCNA Cybersecurity/CCNACBR on February 3, 2026, but the underlying blueprint you need to study - v1.2 - took effect earlier, on January 21, 2025. If you find older material referencing "CyberOps Associate," that content belongs to the same certification lineage and is still relevant as long as it aligns with the v1.2 domains covered here. For a broader introduction to the credential before diving into domain specifics, see What Is CCNA Cybersecurity? and the full CCNA Cybersecurity Certification overview.
The five domains and their weights are:
| Domain | Weight |
|---|---|
| 1. Security Concepts | 20% |
| 2. Security Monitoring | 25% |
| 3. Host-Based Analysis | 20% |
| 4. Network Intrusion Analysis | 20% |
| 5. Security Policies and Procedures | 15% |
Notice how evenly this blueprint is distributed compared to many technical certifications. Four of the five domains sit within a tight 20-25% band, meaning you cannot afford to "skip" a domain and hope to compensate elsewhere. Only Security Policies and Procedures drops to 15%, and even that domain still shows up regularly across the 120-minute session.
Domain 1: Security Concepts (20%)
Security Concepts establishes the vocabulary and frameworks that the rest of the exam assumes you already know. This is the domain most candidates underestimate because it feels conceptual rather than hands-on, yet questions here often set up scenarios that carry into Domain 2 and Domain 4 material.
What Domain 1 Covers
Expect questions on core security principles, threat actor motivations, attack surface concepts, and how cybersecurity operations functions fit into a broader security program.
- The CIA triad and how confidentiality, integrity, and availability trade off in real incidents
- Risk, threat, vulnerability, and exploit terminology used consistently across the exam
- Security data types (session, transaction, statistical, alert, full packet capture) and their evidentiary value
- Encryption fundamentals and their impact on visibility during security monitoring
Because this domain frames everything else, candidates following a structured plan such as the one in the CCNA Cybersecurity Study Guide 2026: How to Pass on Your First Attempt typically tackle Security Concepts first, even though it is not the highest-weighted domain.
Domain 2: Security Monitoring (25%)
Security Monitoring is the single largest domain on the 200-201 CCNACBR exam and deserves the most study hours of any content area. A quarter of your exam questions will draw from this domain, and the v1.2 blueprint specifically expanded it to include modern threat techniques.
What Domain 2 Covers
This domain tests your ability to interpret monitoring data and distinguish legitimate traffic and behavior from indicators of compromise.
- Interpreting NetFlow, packet captures, and log data to identify anomalies
- Recognizing generative-AI-driven social engineering attempts (phishing, pretexting, deepfake-assisted lures)
- Understanding predictive-AI approaches to endpoint monitoring and anomaly detection
- Differentiating false positives, false negatives, true positives, and true negatives in alert triage
- Common attack types visible in monitoring data: DoS, man-in-the-middle, and reconnaissance activity
Given its weight and its newly expanded AI-related content, Security Monitoring is a strong candidate for the "hardest domain" conversation. If you're weighing how challenging the overall exam is likely to feel, the analysis in How Hard Is the CCNA Cybersecurity Exam? Complete Difficulty Guide 2026 breaks this down domain by domain.
Domain 3: Host-Based Analysis (20%)
Host-Based Analysis shifts focus from network traffic to what's happening on individual endpoints. This domain tests whether you can read host-level telemetry - logs, processes, file system activity - and determine whether a system has been compromised.
What Domain 3 Covers
Candidates must be comfortable interpreting endpoint artifacts and mapping them to indicators of compromise or attack.
- Operating system log formats and what they reveal about process execution and privilege changes
- Malware behavior patterns: persistence mechanisms, unusual process trees, suspicious file modifications
- Endpoint security technologies and how their output feeds into a broader monitoring workflow
- Distinguishing between an indicator of compromise and an indicator of attack
Key Takeaway
Practice reading sample host logs and process lists rather than only memorizing definitions - Domain 3 questions are frequently scenario-based, asking you to identify what a given log entry indicates.
Domain 4: Network Intrusion Analysis (20%)
Network Intrusion Analysis asks you to correlate network-level evidence with an attack in progress. Where Domain 2 tests your ability to monitor, Domain 4 tests your ability to analyze what that monitoring has already flagged and determine intent and impact.
What Domain 4 Covers
Expect scenario-driven questions built around packet-level and flow-level evidence.
- Mapping traffic patterns to common attack techniques (scanning, exfiltration, command-and-control communication)
- Correlating multiple data sources to build a coherent picture of an intrusion
- Understanding common evasion and obfuscation techniques used to avoid detection
- Identifying protocol misuse and abnormal application-layer behavior
Because Domains 2 and 4 are closely related in subject matter, many candidates study them back-to-back rather than in isolation, reinforcing overlapping concepts like alert triage and evidence correlation.
Domain 5: Security Policies and Procedures (15%)
The smallest domain by weight, Security Policies and Procedures still requires solid preparation because its content underpins how a security operations team actually functions day to day.
What Domain 5 Covers
This domain moves from technical detection into organizational response and governance.
- Incident response process stages and the roles involved at each stage
- Security policy elements and how they guide operational decision-making
- Chain of custody and evidence-handling procedures relevant to incident investigation
- Compliance frameworks and their influence on monitoring and response priorities
Because this domain carries the lowest weight, some candidates deprioritize it - a mistake, since 15% of a 120-minute exam is still a meaningful share of questions. Once you have a firm grasp of how much you need to answer correctly overall, cross-reference it against CCNA Cybersecurity Passing Score 2026: Exactly What You Need to Pass to understand how domain-level gaps affect your total score.
How to Sequence Your Study Across All Five Domains
A domain-weighted study plan should allocate more time to Security Monitoring than to any other area, but sequencing matters as much as raw hours. Security Concepts terminology underpins the other four domains, so it belongs early in your schedule even though its weight is only 20%.
Security Concepts foundations
- Learn core terminology and data type categories before moving to applied domains
Security Monitoring deep dive
- Spend the most hours here given its 25% weight; include v1.2's AI-related social engineering and endpoint monitoring content
Host-Based Analysis
- Practice reading host logs and identifying compromise indicators
Network Intrusion Analysis
- Build on Security Monitoring skills by correlating network evidence into intrusion timelines
Security Policies and Procedures + full review
- Cover incident response and governance, then run mixed-domain practice questions
Use only original, blueprint-aligned practice questions during review - never reproduced live-exam content, which violates Cisco's confidentiality agreement you accept before testing. A well-structured question bank on our practice test platform lets you drill each domain individually before mixing them together in full-length simulations. For a condensed reference once you've covered every domain once, the CCNA Cybersecurity Cheat Sheet 2026: One-Page Review of Must-Know Facts is useful during final review week.
Who Hires for This Certification
Because the five domains center on security operations center (SOC) workflows - monitoring, host analysis, intrusion analysis, and incident response - the certification maps directly onto entry-level and junior SOC analyst roles, along with related monitoring and triage positions. Employers hiring for these roles are typically evaluating whether a candidate can read logs, recognize indicators of compromise, and follow documented incident response procedures - exactly what Domains 2 through 5 test.
If you're deciding whether to pursue this path at all, weigh the domain content against your career goals using Is the CCNA Cybersecurity Certification Worth It? Complete ROI Analysis 2026, and browse role types more specifically in CCNA Cybersecurity Jobs. Since there are no formal prerequisites, eligibility is rarely the blocker - domain readiness is. Review the CCNA Cybersecurity Requirements 2026: Eligibility, Prerequisites & How to Qualify page if you want full confirmation of what is and isn't required before you register.
Key Takeaway
Certification stays active for three years, and renewal requires 30 Continuing Education credits - passing another associate-level exam alone satisfies this requirement, so ongoing domain knowledge has a direct renewal payoff.
Frequently Asked Questions
Start with Security Concepts (20%). Its terminology and frameworks underpin the other four domains, even though Security Monitoring carries more exam weight.
At 25%, Security Monitoring reflects the core day-to-day work of a SOC analyst. The v1.2 blueprint also expanded it to include generative-AI social engineering and predictive-AI endpoint monitoring, reflecting current threat trends.
No. Security Policies and Procedures is only 15%, but it still represents a meaningful share of a 120-minute, single-attempt exam. Under-preparing any domain risks falling short of the passing score.
The credential lineage traces back to CyberOps Associate, but you must confirm any study material aligns with the current v1.2 blueprint, effective January 21, 2025, especially for the AI-related content added to Security Monitoring.
The exam itself is USD 300 regardless of domain distribution. For a complete breakdown including retake costs and renewal considerations, see CCNA Cybersecurity Certification Cost 2026: Complete Pricing Breakdown.