350-201 exam domains
The 350-201 exam is weighted across 4 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.
| Exam domain | Exam weight | Practice |
|---|---|---|
| Fundamentals | 20% | Practice this topic |
| Techniques | 30% | Practice this topic |
| Processes | 30% | Practice this topic |
| Automation | 20% | Practice this topic |
Sample 350-201 questions
A sample of the 350-201 questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.
- A SOC analyst is asked to detect previously unseen insider threats in authentication logs where no labeled examples of malicious behavior exist. Leade…View question
- A SOC lead wants to reduce the time analysts spend deciding which of thousands of daily alerts to investigate first. The team has years of historical…View question
- A SOC analytics team wants to predict the expected volume of authentication requests for each hour of the coming week so capacity and staffing can be…View question
- A financial services SOC has a large historical dataset of transactions, each already labeled by fraud analysts as either 'fraudulent' or 'legitimate.…View question
- A SOC analyst at a large enterprise is overwhelmed by millions of unlabeled security events per day from firewalls, endpoints, and proxies. Leadership…View question
- A SOC lead is overwhelmed by the volume of unstructured threat intelligence reports, vendor advisories, and dark web forum posts arriving daily. She w…View question
- A SOC engineer is integrating a threat intelligence platform with an internal script. The vendor documentation shows that each request must include an…View question
- A SOC engineer is writing a Python integration against a threat intelligence vendor's REST API. The vendor documentation states that each request must…View question
- A SOC engineer writes a script that submits a list of 5,000 suspicious file hashes to a threat intelligence REST API in a single POST request. The API…View question
- A SOC engineer writes a Python script that queries a threat-intelligence API to enrich indicators. For a batch of 500 IOCs the request consistently fa…View question
Key 350-201 terms
Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the 350-201 exam.
350-201 frequently asked questions
What is the 350-201 certification?+
CBRCOR is the core exam for Cisco’s CCNP Cybersecurity certification (the professional cybersecurity-operations track formerly branded CyberOps Professional).
It targets experienced SOC staff, so success rewards real detection, investigation, and response experience rather than entry-level concepts.
What topics are on the 350-201 exam?+
The CBRCOR exam is organised into four weighted domains. The percentages below are Cisco’s official blueprint weightings, so bias your study toward the two heaviest domains — Techniques and Processes, each 30% of the exam.
Fundamentals (20%)
Covers playbook components and applying playbooks to common scenarios (privilege escalation, DoS/DDoS, defacement), compliance standards (PCI, FISMA, FedRAMP, SOC, SOX, GDPR, ISO 27001), cyber risk insurance, and risk analysis and IR metrics.
Techniques (30%)
One of the two largest domains. Covers AI-powered data-analytic techniques, hardening machine images, evaluating an asset’s security posture, diagnosing control gaps and recommending improvements, and patching and hardening recommendations.
Processes (30%)
One of the two largest domains. Covers threat modeling, investigating common case types, the malware-analysis process (sample extraction, reverse engineering, dynamic/sandbox and static analysis), IOCs, data-loss detection, and vulnerability triage.
Automation (20%)
Covers orchestration and automation concepts and platforms, interpreting and modifying scripts (Python, Bash), common data formats (JSON, HTML, CSV, XML), API constraints (rate limits, timeouts, payload, auth), and CI/CD, DevOps, and infrastructure-as-code for security operations.
Is the 350-201 hard?+
CBRCOR is hard because it is an advanced, judgment-heavy exam: you must apply techniques and processes to realistic incidents, not just recall definitions.
The heavy Techniques and Processes weighting rewards genuine SOC experience with detection, hunting, and incident response. Hands-on operations experience is decisive.
How many questions are on the 350-201 exam and how long is it?+
CBRCOR is a 120-minute exam with a mix of multiple-choice and other item types; Cisco does not publish an exact question count. It is the core exam for CCNP Cybersecurity (formerly CyberOps Professional).
Our full-length practice mock uses a 90-question, 120-minute session so you can rehearse pacing across all four domains before test day.
What score do you need to pass the 350-201?+
Cisco does not publish a fixed passing score for CBRCOR; scaled cut scores are not disclosed and vary by exam form, so the 75% threshold on our practice mock is our own study checkpoint rather than an official cutline. Because there is no guessing penalty, answer every question.
How much does the 350-201 exam cost?+
The CBRCOR exam fee is set by Cisco (around US$400) — check the Cisco site for current pricing. The certification is valid for three years. Everything on this hub is free.
Who should take the 350-201?+
CBRCOR is aimed at experienced SOC analysts, incident responders, and security engineers pursuing CCNP Cybersecurity.
Cisco recommends three to five years of hands-on security-operations experience before attempting it.
What jobs and salaries can the 350-201 lead to?+
CBRCOR maps to roles such as SOC analyst (tier 2/3), incident responder, threat hunter, and security operations lead.
How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. CBRCOR is best viewed as proof of advanced security-operations skill.
How long does it take to study for the 350-201?+
Candidates often need two to four months, spent practicing detection, hunting, incident response, and automation in a real or lab SOC environment.
Review every explanation, including for questions you answered correctly, because CBRCOR distractors are built from plausible but incorrect analysis or process choices. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.
How should you prepare for the 350-201?+
Study the four domains above, giving the heaviest weight to Techniques and Processes, then drill scenario questions domain by domain while practicing with SOC tooling and playbooks. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.
When you can run detection and response comfortably, move to full-length timed mocks. Use the glossary to keep concepts like SIEM/SOAR, MITRE ATT&CK, chain of custody, and playbooks straight, and aim to score consistently above the checkpoint before you book.
Can you take the 350-201 exam online?+
Yes. Cisco delivers 350-201 CBRCOR through Pearson VUE, so you can test at a physical Pearson VUE centre or online with OnVUE remote proctoring. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.
If you do not pass, Cisco enforces a waiting period of five calendar days before you can retake the same exam.
What certification should you take after the 350-201?+
After CBRCOR, you complete CCNP Cybersecurity with a concentration exam focused on your security-operations specialty.
For many, the real next step is leading a SOC. Pairing CBRCOR with hands-on operations is what turns the certificate into a career.