CISCO · 200-201

Cisco 200-201 CCNACBR Exam Practice Questions

462 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 462 questions in this pack

Question 1

Which event is user interaction?

  1. gaining root access
  2. executing remote code
  3. reading and writing file permission
  4. opening a malicious file
Show answer and explanation

Correct answer: D. opening a malicious file

Opening a malicious file is a direct user interaction event, a person actively performs the action that triggers the security incident. The other options represent either system-level compromises (gaining root access, executing remote code) or administrative properties (file permissions) that may occur without user awareness or direct interaction.

Why the other options are wrong

  • A. Gaining root access is a system-level compromise, not a user interaction event.
  • B. Executing remote code is an attacker-driven action, not a user interaction.
  • C. Reading and writing file permissions are system properties, not user interactions.

Question 2

Which security principle requires more than one person is required to perform a critical task?

  1. least privilege
  2. need to know
  3. separation of duties
  4. due diligence
Show answer and explanation

Correct answer: C. separation of duties

Separation of duties is the principle that requires multiple people to complete a critical task, ensuring no single person can perform sensitive operations alone. This provides accountability and prevents fraud. Least privilege limits access scope, need to know restricts information sharing, and due diligence refers to investigative processes, none specifically address the multi-person requirement.

Why the other options are wrong

  • A. Least privilege restricts access levels, not requiring multiple people.
  • B. Need to know limits information distribution to those who require it.
  • D. Due diligence is an investigative and assessment process, not a multi-person control.

Question 3

How is attacking a vulnerability categorized?

  1. action on objectives
  2. delivery
  3. exploitation
  4. installation
Show answer and explanation

Correct answer: C. exploitation

Exploitation is the attack phase in which an attacker actively attacks a vulnerability to gain access or control. This is distinct from delivery (moving the attack tool to the target), installation (establishing persistence), and action on objectives (achieving the attacker's goal after compromise).

Why the other options are wrong

  • A. Action on objectives occurs after successful exploitation, when the attacker pursues their goal.
  • B. Delivery is the phase of transporting the attack tool to the target system.
  • D. Installation is the phase of establishing persistence mechanisms, not attacking the vulnerability itself.

See all 10 free questions Get the full pack, US$39

462 practice questions for Cisco CCNA Cybersecurity (200-201 CCNACBR), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 462 questions across all five 200-201 domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed 200-201 attempt costs another US$300. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 462 questions

What makes the CCNA Cybersecurity hard

The 200-201 tests like a shift in a SOC. It does not ask whether you know what an IDS is; it hands you a packet capture excerpt, a Windows event log or a NetFlow record and asks what the analyst should conclude.

TCP/IP attack surface analysis, reading pcaps and protocol headers, Windows and Linux host artifacts, alert triage and true versus false positives, the Cyber Kill Chain and Diamond Model, and evidence handling, plus the v1.2 additions on AI-powered detection and AI-driven threat intelligence, are all in scope. Candidates who studied theory but have not practised interpreting raw output consistently underperform. Roughly 95 to 105 questions in 120 minutes makes this one of the fastest-paced exams Cisco runs.

About the exam

The 200-201 CCNACBR certifies SOC analysts in security monitoring, host-based and network intrusion analysis, and incident response procedures. It is the single exam required for the CCNA Cybersecurity certification, formerly known as CyberOps Associate (CBROPS), renamed in February 2026 with AI-focused objectives added in exam version v1.2. No formal prerequisites. Valid for three years.

Exam domains

  • Security concepts: 20%
  • Security monitoring: 25%
  • Host-based analysis: 20%
  • Network intrusion analysis: 20%
  • Security policies and procedures: 15%

95 to 105 questions, 120 minutes, variable passing score (Cisco does not publish it), US$300 per attempt, Pearson VUE testing centres or online proctored, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Cisco 200-201 CCNACBR pack?

462 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.