(CCNACBR) Understanding Cisco Cybersecurity Operations Fundamentals

Build vital cybersecurity analyst skills in network monitoring, endpoint security, and threat defense. Launch your SOC career and enroll today.

Duration

5 days

Version

2.0

CE Credits

28

The Cisco Continuing Education Program enables you to renew your certifications while exploring new learning paths and enhancing your skillset. It's a convenient way to stay certified without retaking exams. Click here to learn more.

CLCs

44

Cisco Learning Credits (CLCs) are prepaid training vouchers that can be used as investment into your knowledge. You can attend NIL Learning’s trainings and pay with CLCs. Click here to learn more.

By default, our instructors deliver the courses remotely in real time in English. On-premise delivery and other languages available on request.

Course hero image

Dates and Prices

This course currently does not have any scheduled dates. Contact us for more information.
Price of the course: 2880 €
Contact us
This course currently does not have any scheduled dates. Contact us for more information.
Price of the course: 2880 €
Contact us
What are CLCs (Cisco Learning Credits)?

Cisco Learning Credits (CLCs) are prepaid training vouchers that can be used as investment into your knowledge. You can attend NIL Learning’s trainings and pay with CLCs. Click to learn more.

Course Overview

The Understanding Cisco Cybersecurity Operations Fundamentals (CCNACBR) training provides an understanding of the network infrastructure devices, operations, and vulnerabilities of the TCP/IP protocol suite, and basic information security concepts, common network application operations and attacks, the Windows and Linux operating systems, and the types of data that are used to investigate security incidents. After completing this training, you will have the basic knowledge required to perform the job role of an associate-level cybersecurity analyst in a threat-centric security operations center (SOC).

This training prepares you for the 200-201 CCNACBR exam. If passed, you earn the Cisco Certified Network Associate (CCNA) Cybersecurity certification and the role of a junior or entry-level cybersecurity operations analyst in a SOC. This training also earns you 28 Continuing Education (CE) credits toward recertification.

This training will help you:

  • Gain fundamental skills and hands-on practice to prevent and defend against cyberattacks as part of a SOC team
  • Acquire the basic knowledge required to perform as an associate-level cybersecurity analyst in a threat-centric SOC
  • Understand key security concepts including operating systems, endpoint security, network monitoring, cryptography, and cloud security fundamentals
  • Develop practical skills in threat detection, incident investigation, and using SOC playbooks and response plans through labs and simulations
  • Prepare for the 200-201 CCNACBR exam
  • Earn 28 CE credits toward recertification

Course Instructor Welcome Message

Welcome to Your Path to Mastery!

Hey! Ready to learn and grow? I'm here to help you every step of the way!

Robert Lesar

Lead Instructor

Instructor Image
x

Didn’t find what you were looking for?

If you’re interested in training for teams, specific language or on-premise delivery, don’t hesitate to contact us. We will try to accommodate all your expectations to get you the best training experience.

Contact us

Objectives

Gain expert IT skills with NIL Learning: Benefit from our blend of theory and practical experience. Enhance your growth with insights into current and future tech trends. Choose us for cutting-edge Cisco training and more, taught by field-proven experts to maximize your training investment.

  • Explain the foundational aspects of SOCs, including their types, key roles, and essential metrics for measuring effectiveness
  • Apply foundational security principles and risk management concepts to assess and protect organizational assets
  • Compare and apply various access control models to secure network resources and enforce organizational policies
  • Differentiate between various cloud deployment and service models and explain the shared responsibility for security in cloud environments
  • Explain the fundamental concepts of cryptography, differentiate between various cryptographic algorithms, and explain how cryptographic principles are applied in real-world protocols and systems, including key exchange, digital signatures, and SSL/TLS
  • Identify and describe the fundamental components and operational aspects of the Windows operating system for security analysis
  • Identify and describe the fundamental components and operational aspects of the Linux operating system for security analysis
  • Utilize Command Line Interfaces (CLIs) for basic system interaction, file management, and security-related tasks in both Windows and Linux environments
  • Explain the operations and identify the security implications of foundational network protocols
  • Describe and differentiate various network security controls and their application in protecting network infrastructure
  • Differentiate between various Intrusion Detection and Prevention Systems (IDS/IPS) and interpret their output for security monitoring
  • Describe and compare various endpoint security solutions and their effectiveness against common threats
  • Identify and categorize various cyber threat actors based on their motivations, capabilities, and common tactics
  • Explain the phases of the Classic Cyber Kill Chain model and identify adversary actions within each phase
  • Apply the MITRE ATT&CK Framework to analyze and map cyber threats, explain its structure and application, and leverage it to enhance threat detection, incident response, and communication within a security operations environment
  • Identify and describe various social engineering attack vectors, including those enhanced by generative AI
  • Describe fundamental network attack techniques that exploit protocol vulnerabilities
  • Describe advanced attack vectors and emerging threats in the current cybersecurity landscape
  • Identify and explain various types of Network Security Monitoring (NSM) data and their role in incident investigation
  • Identify and interpret various log data sources from operating systems, network devices, and security tools
  • Explain NetFlow operations and its application as a security tool for network monitoring and anomaly detection
  • Describe common web application attacks and their exploitation methods
  • Apply advanced log analysis techniques to interpret security data and identify patterns of suspicious behavior
  • Perform packet capture analysis and apply digital forensics processes to investigate security incidents. Focus on the 5-tuple and timestamps to correlate with other logs, as this is your primary tool for network forensics
  • Explain malware analysis outputs and apply threat intelligence frameworks for security investigations
  • Explain the architecture, core functions, and best practices for implementing SIEM solutions for effective security monitoring
  • Explain the features and common use cases of SOAR platforms for automating and streamlining incident response
  • Explain the Cisco XDR platform, its core functions, features, and components for unified threat detection and response
  • Differentiate between the legacy and modern NIST incident response guidance (NIST SP 800-61 Rev 2 and NIST SP 800-61 Rev 3 special publications), describe core IR components aligned with the NIST CSF 2.0 framework, and identify how these practices satisfy CMMC requirements for the Defense Industrial Base (DIB)
  • Describe the roles, categories, and operational services of Computer Security Incident Response Teams (CSIRTs)
  • Explain the concept of security monitoring playbooks and their components for standardizing incident response
  • Apply various threat hunting methodologies to proactively identify and mitigate hidden threats within a network

Who should enroll?

  • Associate-Level Cybersecurity Analysts

Course benefits:

Get expert knowledge

Our learning programs are designed and led by expert IT engineers, consultants and instructors. We constantly implement participants’ feedback to improve our courses.

Our experiences build your competencies

With 30+ years of experience, we’ve been on the market as long as Cisco. Our understanding of IT systems and industry job demands gives us the insight to guide you towards becoming a world-class expert yourself.

Rise above the industry average

Cisco courses are intended not only for you to pass the certification exam, but to develop your skills and rise above the industry average. Our instructors provide you with guidance and references that allow you to grow into a confident and competent professional.

Retain the knowledge longer

In-depth, non-interrupted learning program ensures you know the bigger picture and retain the knowledge long term. It also reduces the risk of information loss and confusion.

Learn from the best in Cisco technologies

Our IT consultants-turned-instructors have years of experience and dedicated time to Their hands-on project involvement brings practical expertise to our learning programs.

Have peace of mind

We deliver on our promise and on schedule. Rest assure our instructors will give you the knowledge, information, hints and practical experiences around the specific topics. Based on global survey, conducted by Cisco, NIL Learning instructors enjoy an average score 9.54 out of 10.

Be ahead of the curve

As Cisco Platinum Learning Partner and technical community member, we’re the ones who create learning content for major technological vendors. NIL Learning is among the first to offer you high-quality learning and training courses Cisco Technologies.

Get more from a training

Our instructors deliver the courses with practical and useful examples from real-life situations. All NIL Learning instructors are field-proven experts – each both an active engineer and instructor.

Courses delivered by experts for experts in the making.

Among the first to offer training on newly arrived Cisco technologies

Part of Conscia, leading European IT solutions and services provider

A tech powerhouse with 30+ years of training & field experience

Industry-acclaimed, broadly expertised, and technically proficient

Connecting you with future trusted industry advisors

Course Outline

  • Security Operations
  • Security Principles
  • Access Control Models
  • Cloud Security Models
  • Cryptography for Security Operations
  • Windows OS Basics
  • Linux OS Basics
  • CLIs in Security
  • Network Protocols
  • Network Security Controls
  • IDS and IPS
  • Endpoint Security
  • Threat Actors
  • Cyber Kill Chain Model
  • MITRE Attack Framework
  • Social Engineering Attacks
  • Network Attack Fundamentals
  • Advanced Threat Landscape
  • Network Security Monitoring (NSM) Data
  • Log Data Sources
  • NetFlow for Security Monitoring
  • Web Application Attacks
  • Advanced Log Analysis
  • Packet Capture and Forensics
  • Malware and Threat Intelligence
  • Security Information and Event Management (SIEM)
  • Security Orchestration, Automation, and Response (SOAR)
  • Extended Detection and Response (XDR)
  • Incident Response Planning
  • CSIRT Roles and Operations
  • Security Monitoring Playbooks
  • Threat Hunting Methodologies

Lab Outline

  • Explore Cryptographic Technologies
  • Explore the Windows Operating System
  • Explore the Linux Operating System
  • Explore Endpoint Security
  • Investigate Hacker Methodology
  • Explore TCP/IP Attacks
  • Investigate Advanced Persistent Threats
  • Use NSM Tools to Analyze Data Categories
  • Analyze Suspicious DNS Activity
  • Investigate Browser-based Attacks
  • Correlate Event Logs, PCAPs, and Alerts of an Attack
  • Explore SOC Playbooks
  • Hunt Malicious Traffic

Prerequisite Knowledge

There are no prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:

  • Familiarity with Ethernet and TCP/IP networking
  • Working knowledge of the Windows and Linux operating systems
  • Familiarity with basics of networking security concepts

These skills can be found in the following training:

Looking for something different?

Reach out to us to discuss your learning needs. We’ve got you covered.

Contact us

Course instructors

Knowledge is your greatest power. And it resides in the people that lead our courses.

Why NIL?

Global Leading Provider of Cisco Courses

30+ years of experience

Since 1992, NIL has been at the forefront of advanced contributors to strategic partner Cisco technologies, learning curriculum and value-added solutions deployed to clients around the globe.

Learn more about us
A woman working on her computer
FAQ

A remote lab is a virtual environment that provides access to Cisco equipment and software for hands-on practice. It allows learners to simulate real-world scenarios and apply what they have learned in a controlled setting, all from a remote location.

Labs work by providing a set of tasks or exercises that learners must complete using the remote lab environment. These tasks are designed to reinforce theoretical knowledge through practical application, often using real or simulated Cisco hardware and software configurations.

Access to labs is provided to learners by an instructor at the beginning of the training.

Access to the remote lab is limited to the duration of the course.

Accessing a remote lab requires a stable internet connection and a compatible web browser. Some labs may also require specific software or plugins to be installed on your computer. Detailed system requirements are provided in advance.

Not every course includes a remote lab. Whether a course includes a remote lab depends on the course’s objectives and structure. Courses focused on practical skills or technical certifications are more likely to include remote labs. Each training has lab exercises listed in its description.

To access the Course Book or Student Guide, you must have an active Cisco.com ID (CCO ID). Access details are provided a few days before the start date of the training and on the first day of the training by the instructor (in case an email from Cisco is missed).

Access to the Course Book (Student Guide) is related to the learners’s CCO ID and is valid for the life of a specific course.

Reach out to our team!

For any additional information, team training or language options, write to our team! We’re eager to help you meet your learning goals.

Contact us