- The current exam is 200-201 CCNACBR v1.2, 120 minutes, USD 300, delivered via Pearson VUE.
- Security Monitoring is the heaviest domain at 25%, now including generative-AI social engineering topics.
- A failed attempt requires a five-calendar-day wait before retaking, at the same USD 300 fee.
- No prerequisites exist, so first-attempt success depends entirely on disciplined domain-based preparation.
What Changed in the 200-201 v1.2 Blueprint
If you studied this credential years ago under an older name, you need to reorient before you open a single practice question. The v1.2 blueprint took effect January 21, 2025, and the certification's own acronym shifted from Cybersecurity Associate/CBROPS to CCNA Cybersecurity/CCNACBR on February 3, 2026. If your search history is full of "CyberOps Associate," you're looking at the same certification lineage - just a rebranded exam code and an updated content outline.
The practical impact for candidates: Security Monitoring, already the largest domain, now explicitly folds in generative-AI-driven social engineering scenarios and predictive-AI endpoint monitoring concepts. This isn't a cosmetic tweak. If your study material predates 2025, it almost certainly skips these topics entirely, and you'll walk into the test center with a blind spot in exactly the section worth the most points. For a full walkthrough of how each domain was reshaped, see the CCNA Cybersecurity Exam Domains 2026 guide.
Exam Format, Registration, and Fees
Cisco Systems administers the certification, but all scheduling and delivery runs through Pearson VUE - either at an authorized test center or via OnVUE online proctoring from home. There are no formal prerequisites and no mandatory training, which means the barrier to entry is low but the responsibility for preparation sits entirely on you.
- Exam code: 200-201 CCNACBR, Understanding Cisco Cybersecurity Operations Fundamentals v1.2
- Cost: USD 300 per attempt, English only
- Duration: 120 minutes, computer-delivered, closed-book
- Scoring: Pass/fail, with results posted online within 48 hours
- Retake policy: Five full calendar days of waiting, starting the day after a failed attempt, before you can retake - at the same USD 300 fee
Before you sit down at the keyboard, you'll accept Cisco's confidentiality agreement and go through standard identification and proctoring checks. Treat this like any other secure, closed-book professional exam: no notes, no reference sheets, no second monitor if you're testing via OnVUE. For a granular cost comparison across retake scenarios, check the CCNA Cybersecurity Certification Cost breakdown, and if you're still confirming basic eligibility, the Requirements guide covers it directly.
Key Takeaway
Because there's no waiting period before your first attempt but a mandatory five-day gap after a failed one, front-load your preparation. Treat attempt one as the only attempt you plan to need.
Domain-by-Domain Study Priorities
The 200-201 exam is built around five domains, each with distinct weight. Allocating study hours proportionally - instead of spreading effort evenly - is the single biggest lever you control before test day.
Domain 1: Security Concepts (20%)
Covers the foundational vocabulary and frameworks examiners assume you already know before tackling monitoring and analysis questions.
- CIA triad application in real scenarios, not just definitions
- Risk, threat, vulnerability, and exploit terminology used precisely
- Security data types: full packet capture, session data, alert data, transaction data
Domain 2: Security Monitoring (25%)
The largest domain and the one most affected by the v1.2 update. Expect scenario questions that test whether you can distinguish legitimate anomalies from noise.
- Generative-AI-enabled social engineering: recognizing AI-crafted phishing and pretexting patterns
- Predictive-AI endpoint monitoring behavior and how it changes alert triage
- Network protocols and their security monitoring implications (DNS, HTTP/S, ICMP)
Domain 3: Host-Based Analysis (20%)
Focuses on interpreting evidence from endpoints rather than the wire.
- Operating system log interpretation across Windows and Linux
- Malware indicators of compromise on a host
- Endpoint security technologies and how they report events
Domain 4: Network Intrusion Analysis (20%)
Tests your ability to read network-based evidence and map it to attacker behavior.
- Packet and PCAP analysis to identify intrusion artifacts
- Correlating alerts with underlying network traffic
- Differentiating false positives from confirmed intrusions
Domain 5: Security Policies and Procedures (15%)
The smallest domain by weight but still a guaranteed presence on every exam form.
- Incident response process stages and documentation requirements
- Regulatory and compliance frameworks referenced in SOC operations
- Playbook and runbook usage during an active investigation
For candidates deciding how much total effort this represents, the Difficulty Guide and Pass Rate analysis both offer useful context beyond this study guide.
A Realistic Study Timeline
Generic study techniques - timeboxing, self-explanation, spaced review - only matter if they're mapped to the actual weight of each domain. Here's a sequencing approach that front-loads Security Monitoring given its 25% share, while still leaving room to reinforce weaker areas before test day.
Security Concepts + Security Monitoring foundations
- Build vocabulary fluency for Domain 1 terminology
- Start Domain 2 with traditional monitoring data types before layering in AI-related topics
Security Monitoring deep dive (AI content) + Host-Based Analysis
- Study generative-AI social engineering patterns and predictive-AI endpoint monitoring specifically
- Move into Domain 3 log and host artifact interpretation
Network Intrusion Analysis + Security Policies
- Practice PCAP-style scenario questions for Domain 4
- Cover incident response and compliance basics for Domain 5
Full-length review and weak-area repair
- Run timed practice sets across all five domains
- Revisit only the domains where scores lag before scheduling your Pearson VUE slot
Before you lock in a date, review the Exam Dates and Scheduling guide so testing-center availability doesn't force you to sit the exam before you're ready.
Question Style: What the Exam Actually Asks
The 200-201 exam is a computer-delivered, proctored written examination - not a lab-based or performance exam. Expect multiple-choice and scenario-based items that present a log excerpt, packet summary, or incident description and ask you to identify the correct classification, next step, or root cause. Domain 2 and Domain 4 questions in particular tend to embed short technical artifacts you must interpret under time pressure, so reading speed and pattern recognition matter as much as raw memorization.
Passing is determined on a pass/fail basis with no publicly disclosed numeric cut score breakdown by domain, so don't over-index on hitting an exact percentage in any one area - focus on consistent competence across all five. The Passing Score guide explains how scoring works in more detail.
| Domain | Weight | Primary Skill Tested |
|---|---|---|
| Security Concepts | 20% | Foundational terminology and data types |
| Security Monitoring | 25% | Anomaly detection, including AI-driven threats |
| Host-Based Analysis | 20% | Endpoint log and artifact interpretation |
| Network Intrusion Analysis | 20% | Packet-level evidence correlation |
| Security Policies and Procedures | 15% | Incident response and compliance process |
Practice Strategy Without Live-Exam Content
Cisco's exam is closed-book and governed by a confidentiality agreement, which means any "practice question" claiming to be lifted directly from a live exam form is both unreliable and a violation of that agreement. The safer, more durable approach is to use original, blueprint-aligned practice questions written specifically against the current 200-201 v1.2 outline - not recycled dumps of unknown origin and unknown accuracy.
You can build a solid rotation using the domain breakdowns above, a current Cisco Press v1.2 supplement, and structured practice sets at our CCNA Cybersecurity practice test platform, which tracks performance by domain so you can see exactly where Domain 2 or Domain 4 scores are lagging before you spend USD 300 on an attempt. Running full 120-minute timed sessions at the practice site also builds the pacing stamina the real exam demands.
After Passing: Renewal and Career Paths
Once you pass, the certification stays active for three years. Renewal requires 30 Continuing Education credits, and here's the convenient part: passing an associate-level certification exam - including a future recertification attempt - automatically earns the full 30 credits needed. Eligible training and other approved activities also count, so you have flexibility beyond simply retesting.
On the career side, this credential is aimed squarely at entry-level security operations roles: SOC analyst tier-1/tier-2 positions, junior incident response, and network security monitoring seats where reading logs, packets, and alerts is the daily job. If you're weighing whether the investment lines up with hiring demand, the Jobs guide and Salary Guide break down where this credential typically opens doors, and the ROI Analysis puts the USD 300 fee in context against career outcomes.
If you're still confirming exactly what this certification is and how it differs from similarly named credentials elsewhere, start with What Is CCNA Cybersecurity? or the Certification overview before committing to a study plan.
Frequently Asked Questions
No. Cisco sets no formal prerequisites and no required training for this certification. Anyone can register directly through Pearson VUE.
You must wait five full calendar days, starting the day after your failed attempt, before scheduling a retake. The retake costs the same USD 300 as the original exam.
The content and format are identical either way. You can test at an authorized Pearson VUE center or remotely through OnVUE online proctoring, subject to the same identification and confidentiality rules.
At 25%, it's the largest of the five domains and reflects the core day-to-day work of a SOC analyst: detecting anomalies, including newer generative-AI social engineering and predictive-AI endpoint monitoring scenarios added in the v1.2 blueprint.
The certification is active for three years. Renewal requires 30 Continuing Education credits, which you automatically earn by passing an associate-level certification exam, or by completing eligible training and other approved activities.