In this Performing Cybersecurity Using Cisco Security Technologies course provides a comprehensive introduction to modern Security Operations Center practices, focusing on how security teams detect, analyze, investigate, and respond to cyber threats across enterprise and cloud environments. It is designed for SOC analysts, security engineers, and incident responders who need to understand the full security operations lifecycle, from risk management and detection to investigation, threat hunting, and response. The course emphasizes structured analytical processes, repeatable playbooks, and hands-on investigation techniques.
Students begin by exploring risk management concepts, SOC operations, analytical workflows, and playbooks, establishing a foundation for effective security monitoring and decision-making. The curriculum then examines enterprise assets, cloud security responsibility models, APIs, and SOC deployment models to provide context for security operations. Technical investigation skills are developed through packet capture analysis, network traffic inspection, and log analysis from endpoints and security appliances, with an emphasis on threat tuning to improve detection accuracy and reduce false positives.
Advanced topics include threat research, threat intelligence platforms, security analytics, malware forensics, and threat hunting fundamentals aligned with frameworks such as MITRE ATTACK®. The course culminates in incident investigation and response, where students validate attacks, analyze indicators of compromise, and execute structured response actions. Extensive hands-on labs using tools such as Cisco XDR, Cisco Firepower, Splunk Phantom, and threat intelligence platforms reinforce real-world SOC workflows, preparing learners to operate effectively in a modern, threat-centric SOC environment.
How You'll Benefit This training will help you:
Develop essential cybersecurity skills in SOC operations, threat detection, and incident response through real-world labs and scenarios
Gain hands-on experience with leading security tools such as Cisco XDR, Splunk Phantom, and Firepower NGFW
Learn automation and SecDevOps practices to improve efficiency and effectiveness in security operations
Upon completing this course, the student will be able to:
Describe the types of service coverage within a SOC and operational responsibilities associated with each
Compare security operations considerations of cloud platforms
Describe the general methodologies of SOC platforms development, management, and automation
Describe asset segmentation, segregation, network segmentation, microsegmentation, and approaches to each, as part of asset controls and protections
Describe Zero Trust and associated approaches, as part of asset controls and protections
Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC
Use different types of core security technology platforms for security monitoring, investigation, and response
Describe the DevOps and SecDevOps processes
Describe the common data formats (e.g., JavaScript Object Notation (JSON), HTML, XML, and Comma-Separated Values (CSV))
Describe API authentication mechanisms
Analyze the approach and strategies of threat detection, during monitoring, investigation, and response
Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs)
Interpret the sequence of events during an attack based on analysis of traffic patterns
Describe the different security tools and their limitations for network analysis (e.g., packet capture tools, traffic analysis tools, and network log analysis tools)
Analyze anomalous user and entity behavior (UEBA)
Perform proactive threat hunting following best practices
What to Expect in the Exam
Performing Cybersecurity Using Cisco Security Technologies (350-201 CBRCOR) v1.2 is a 120-minute exam associated with the Cisco Certified Specialist – Cybersecurity Core certification and satisfies the core exam requirement for the Cisco Certified Cybersecurity Professional certification.
This exam tests your knowledge of core cybersecurity operations, including: