Build cybersecurity skills needed to detect threats, investigate incidents, and defend modern enterprise environments.

Cybersecurity professionals play a critical role in identifying threats, monitoring security events, and protecting organizations against evolving cyberattacks.

This Cisco CCNA Cybersecurity certification provides the practical knowledge required to work in a Security Operations Center (SOC), combining networking fundamentals with security monitoring, incident investigation, endpoint protection, cloud security, and threat analysis to prepare learners for real-world cybersecurity operations.

  • Why get trained: Learn how to monitor security events, investigate incidents, analyze network and endpoint activity, apply security controls, understand cloud security, use cryptography, and support SOC operations through practical labs aligned to the Cisco 200-201 CCNACBR certification exam.
  • Why it matters: This certification validates the foundational skills needed for Security Operations Center (SOC) roles while preparing learners to defend enterprise networks using industry-recognized security practices.
  • Who should attend: Associate Cybersecurity Analysts, SOC Analysts, Network Administrators, Network Engineers, IT Support Professionals, Security Administrators, Incident Response Teams, and individuals pursuing an entry-level cybersecurity career.

Build the practical cybersecurity knowledge required to launch a career in Security Operations Centers and prepare confidently for the Cisco CCNA Cybersecurity certification. HRD Corp Claimable.

Overview

The Understanding Cisco Cybersecurity Operations Fundamentals (CCNACBR) training provides an understanding of the network infrastructure devices, operations, and vulnerabilities of the TCP/IP protocol suite, and basic information security concepts, common network application operations and attacks, the Windows and Linux operating systems, and the types of data that are used to investigate security incidents.

After completing this training, you will have the basic knowledge required to perform the job role of an associate-level cybersecurity analyst in a threat-centric security operations center (SOC).

This training prepares you for the 200-201 CCNACBR exam. If passed, you earn the Cisco Certified Network Associate (CCNA) Cybersecurity certification and the role of a junior or entry-level cybersecurity operations analyst in a SOC.

Skills Covered

After taking this course, you should be able to:

  • Explain the foundational aspects of SOCs, including their types, key roles, and essential metrics for measuring effectiveness
  • Apply foundational security principles and risk management concepts to assess and protect organizational assets
  • Compare and apply various access control models to secure network resources and enforce organizational policies
  • Differentiate between various cloud deployment and service models and explain the shared responsibility for security in cloud environments
  • Explain the fundamental concepts of cryptography, differentiate between various cryptographic algorithms, and explain how cryptographic principles are applied in real-world protocols and systems, including key exchange, digital signatures, and SSL/TLS
  • Identify and describe the fundamental components and operational aspects of the Windows operating system for security analysis
  • Identify and describe the fundamental components and operational aspects of the Linux operating system for security analysis
  • Utilize Command Line Interfaces (CLIs) for basic system interaction, file management, and security-related tasks in both Windows and Linux environments
  • Explain the operations and identify the security implications of foundational network protocols
  • Describe and differentiate various network security controls and their application in protecting network infrastructure
  • Differentiate between various Intrusion Detection and Prevention Systems (IDS/IPS) and interpret their output for security monitoring
  • Describe and compare various endpoint security solutions and their effectiveness against common threats
  • Identify and categorize various cyber threat actors based on their motivations, capabilities, and common tactics
  • Explain the phases of the Classic Cyber Kill Chain model and identify adversary actions within each phase
  • Apply the MITRE ATT&CK Framework to analyze and map cyber threats, explain its structure and application, and leverage it to enhance threat detection, incident response, and communication within a security operations environment
  • Identify and describe various social engineering attack vectors, including those enhanced by generative AI
  • Describe fundamental network attack techniques that exploit protocol vulnerabilities
  • Describe advanced attack vectors and emerging threats in the current cybersecurity landscape
  • Identify and explain various types of Network Security Monitoring (NSM) data and their role in incident investigation
  • Identify and interpret various log data sources from operating systems, network devices, and security tools
  • Explain NetFlow operations and its application as a security tool for network monitoring and anomaly detection
  • Describe common web application attacks and their exploitation methods
  • Apply advanced log analysis techniques to interpret security data and identify patterns of suspicious behavior
  • Perform packet capture analysis and apply digital forensics processes to investigate security incidents. Focus on the 5-tuple and timestamps to correlate with other logs, as this is your primary tool for network forensics
  • Explain malware analysis outputs and apply threat intelligence frameworks for security investigations
  • Explain the architecture, core functions, and best practices for implementing SIEM solutions for effective security monitoring
  • Explain the features and common use cases of SOAR platforms for automating and streamlining incident response
  • Explain the Cisco XDR platform, its core functions, features, and components for unified threat detection and response
  • Differentiate between the legacy and modern NIST incident response guidance (NIST SP 800-61 Rev 2 and NIST SP 800-61 Rev 3 special publications), describe core IR components aligned with the NIST CSF 2.0 framework, and identify how these practices satisfy CMMC requirements for the Defense Industrial Base (DIB)
  • Describe the roles, categories, and operational services of Computer Security Incident Response Teams (CSIRTs)
  • Explain the concept of security monitoring playbooks and their components for standardizing incident response
  • Apply various threat hunting methodologies to proactively identify and mitigate hidden threats within a network

Prerequisites

There are no prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:

  • Familiarity with Ethernet and TCP/IP networking
  • Working knowledge of the Windows and Linux operating systems
  • Familiarity with basics of networking security concepts

These skills can be found in the following Cisco Learning Offerings:

Target Audience

  • Associate-level cybersecurity analysts

Course Curriculum

Outline

  • Security Operations
  • Security Principles
  • Access Control Models
  • Cloud Security Models
  • Cryptography for Security Operations
  • Windows OS Basics
  • Linux OS Basics
  • CLIs in Security
  • Network Protocols
  • Network Security Controls
  • IDS and IPS
  • Endpoint Security
  • Threat Actors
  • Cyber Kill Chain Model
  • MITRE Attack Framework
  • Social Engineering Attacks
  • Network Attack Fundamentals
  • Advanced Threat Landscape
  • Network Security Monitoring (NSM) Data
  • Log Data Sources
  • NetFlow for Security Monitoring
  • Web Application Attacks
  • Advanced Log Analysis
  • Packet Capture and Forensics
  • Malware and Threat Intelligence
  • Security Information and Event Management (SIEM)
  • Security Orchestration, Automation, and Response (SOAR)
  • Extended Detection and Response (XDR)
  • Incident Response Planning
  • CSIRT Roles and Operations
  • Security Monitoring Playbooks
  • Threat Hunting Methodologies

Lab outline

  • Explore Cryptographic Technologies
  • Explore the Windows Operating System
  • Explore the Linux Operating System
  • Explore Endpoint Security
  • Investigate Hacker Methodology
  • Explore TCP/IP Attacks
  • Investigate Advanced Persistent Threats
  • Use NSM Tools to Analyze Data Categories
  • Analyze Suspicious DNS Activity
  • Investigate Browser-based Attacks
  • Correlate Event Logs, PCAPs, and Alerts of an Attack
  • Explore SOC Playbooks
  • Hunt Malicious Traffic

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

August 10, 2026 - August 14, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 1350

August 10, 2026 - August 14, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 1350

October 12, 2026 - October 16, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 1350

October 12, 2026 - October 16, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 1350

December 14, 2026 - December 18, 2026

Location: Kuala Lumpur
Modal: ILT
Availability: TBC
Exam:
RM 1350

December 14, 2026 - December 18, 2026

Location: Online
Modal: VILT
Availability: TBC
Exam:
RM 1350
Trainocate exam and cert

Exam & Certification

Cisco Certified CCNA Cybersecurity

Prove your expertise in essential cybersecurity skills, concepts, and technologies, including security monitoring, analysis, and response. Launch your career in cyber operations with the CCNA Cybersecurity certification.

With a CCNA Cybersecurity certification, you’ll prove your expertise in essential cybersecurity skills, concepts, and technologies, including understanding IT infrastructure, operations, and vulnerabilities.

  • Security concepts: Demonstrate your knowledge of security terms like malware, threat hunting, and zero trust. Differentiate security concepts such as vulnerability and exploit.
  • Security monitoring: Understand the technologies used to monitor cybersecurity. Be able to identify attacks on network, web application, social engineering, and endpoints.
  • Host-based analysis:  Identify the endpoints and systems protected by cybersecurity. Attribute the sources of cyber attacks and analyze key evidence, like logs and reports.
  • Network intrusion analysis: Demonstrate your knowledge of troubleshooting techniques and analysis, including assessing event and alert impact, monitoring traffic, and interpreting regular expressions.

Training & Certification Guide

Passing this exam earns you the CCNA Cybersecurity certification, and can also can be used towards your recertification goals.

Understanding Cisco Cybersecurity Operations Fundamentals (200-201 CCNACBR) v1.2 is a 120-minute exam that certifies a candidate’s knowledge and skills related to security concepts, security monitoring, hostbased analysis, network intrusion analysis, and security policies and procedures.

Network security engineer: Identify security vulnerabilities, and develop security systems and procedures to defend against all types of cybercrime.

Security operations center (SOC) analyst: Assess security vulnerabilities, respond to alerts, and prevent unauthorized access to company information.

IT security operations specialist: Implement security measures and collaborate with IT team members to assess risks and prevent security breaches.

Frequently Asked Questions

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes