Cisco CCNA Cybersecurity 200-201: mastering cybersecurity operations fundamentals
Security alerts need to lead to relevant analysis and action. Structure detection, triage and investigation to separate useful signals from noise. Strengthen your ability to document incidents and coordinate response within your defence arrangements.
- Duration
- 5 days 35 hours
- Code
- CCNA-C Code
- Certification
- Cisco CCNA Cybersecurity Certification
Accredited training for the Cisco CCNA Cybersecurity certification.
Presentation
With cyberthreats everywhere, organisations face increasingly sophisticated attacks on critical assets. Without proactive monitoring and rigorous analysis, major intrusions can remain undetected and seriously compromise digital infrastructure security.
This 5-day Cisco CCNA Cybersecurity course prepares you to join or lead a security operations centre (SOC). Through immersive practical exercises and multiple-choice assessments, you will learn to identify, analyse and respond to incidents using advanced tools from the Cisco ecosystem.
By the end, you will be prepared to take the CCNACBR 200-201 certification exam, fully included in our offer (see the Certification tab for details). This certification validates your expertise for work as a cybersecurity analyst in a modern SOC team.
Objectives
By the end of this Cisco CCNA Cybersecurity course, you will be able to:
- Understand security concepts, common vulnerabilities and network attack types.
- Identify SOC monitoring services and tools.
- Analyse network telemetry and event logs to detect suspicious behaviour.
- Master host-based analysis to identify endpoint compromise.
- Develop expertise in network intrusion analysis and security protocols.
- Apply incident response procedures using NIST and SANS frameworks.
- Understand digital forensics and evidence analysis principles.
- Use automation and AI to optimise security alert triage.
- Prepare for and pass 200-201 v1.2 to earn Cisco Certified Cybersecurity Associate certification.
Program
Module 1: mastering security concepts
- Analysing the threat landscape and threat modelling.
- Understanding software vulnerabilities, exploits and indicators of compromise (IoCs).
- Introduction to cryptography: encryption, hashing and PKI certificates.
- The CIA triad and defence-in-depth principles.
Practical exercises
- Identify threats and vulnerabilities using CVE databases and threat intelligence tools.
Case study
- Map the lifecycle of a real intrusion using the Cyber Kill Chain model.
Module 2: monitoring security
- SOC architectures and telemetry technologies.
- Using SIEM platforms such as Splunk and ELK, and network capture tools.
- Monitoring protocols: Syslog, NetFlow and IPFIX.
- Analysing network telemetry to identify suspicious traffic.
Practical exercises
- Navigate a SIEM interface to correlate security events and generate alerts.
Module 3: performing host-based analysis
- Analysing processes, memory and system records in Windows and Linux.
- Identifying persistence and privilege escalation techniques.
- Deployment and analysis using EDR and XDR solutions.
- Forensic analysis principles for compromised endpoints.
Practical exercises
- Extract software artefacts and analyse system logs to identify malware execution.
Module 4: analysing network intrusions
- Interpreting network packet formats and protocols: TCP, IP, DNS and HTTP/S.
- In-depth PCAP analysis with Wireshark.
- Operation and analysis of IDS and IPS alerts: Snort and Zeek.
- Encrypted traffic analysis and SSL/TLS inspection challenges.
Practical exercises
- Isolate and analyse data exfiltration from a complex network capture.
Module 5: applying security policies and procedures
- Incident management using NIST SP 800-61.
- Response stages: preparation, detection, containment and recovery.
- Introduction to SOAR automation and the impact of generative AI on cyber operations.
- Compliance, analytical ethics and sensitive data management.
Practical exercises
- Apply a containment playbook after detecting an active threat.
Audience
This course is designed for IT security and digital operations professionals, including:
- Junior SOC analysts seeking formal validation of technical skills and progression into incident response.
- Network and system administrators incorporating security into day-to-day infrastructure management.
- Entry-level security engineers seeking a structured detection methodology to turn alerts into actionable intelligence.
- Students and IT newcomers seeking a certification-based technical foundation for a cybersecurity operations career.
Prerequisites
To attend this course, you should have:
- IT skills: practical computer proficiency, including navigating Windows and Linux operating systems.
- Theoretical foundations: basic IP addressing and Internet knowledge; CCNA-level knowledge is recommended.
- Language skills: technical English is strongly recommended for official materials and the exam.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
- Certified expertise: delivered to the standards of our certification partner Fast Lane, providing high-level expertise.
- Intensive labs: access to simulated SOC environments for practical use of detection tools.
- Voucher included: the official CCNA Cybersecurity 200-201 v1.2 exam is fully included.
- Cisco Learning Credits: eligible for payment using 43 CLC.
- 2026 approach: the programme incorporates the latest generative AI-assisted analysis methodologies.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Cisco is a registered trademark of Cisco Systems, Inc. in the United States and other countries.
fr
en