350-201 cheat sheet

A one-page reference for the Cisco CCNP Cybersecurity CBRCOR (350-201) exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
Cisco
Level
Professional
Questions
90
Time
120 min
Mock pass mark
75%
Domains
4
Practice Qs
147
Code
350-201

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

SOC
A Security Operations Center (SOC) is the team and facility that monitors, detects, and responds to security incidents. CBRCOR validates advanced SOC analyst skills across techniques, processes, and automation.
SIEM
A Security Information and Event Management (SIEM) system aggregates and correlates logs and alerts to detect threats. CBRCOR covers using SIEM data in detection and investigation techniques.
SOAR
Security Orchestration, Automation, and Response (SOAR) automates incident-response playbooks to accelerate detection and containment. CBRCOR's Automation domain covers SOAR and playbook automation.
Playbook
A Playbook is a documented, often automated sequence of response actions for a specific incident type. CBRCOR covers building and running playbooks as part of SOC processes and automation.
Incident Response
Incident Response is the structured process of detecting, analyzing, containing, eradicating, and recovering from security incidents. CBRCOR's Processes domain centers on the incident-response lifecycle.
Threat Hunting
Threat Hunting is the proactive, hypothesis-driven search for threats that have evaded automated detection. CBRCOR covers threat-hunting techniques as an advanced SOC skill.
Threat Intelligence
Threat Intelligence is curated information about adversaries, their infrastructure, and indicators used to inform detection and response. CBRCOR covers consuming and applying threat intelligence in SOC processes.
MITRE ATT&CK
MITRE ATT&CK is a knowledge base of adversary tactics and techniques used to map, detect, and reason about attacks. CBRCOR uses ATT&CK to structure detection and threat-hunting techniques.
IOC
An Indicator of Compromise (IOC) is an artifact — such as a hash, IP, or domain — that signals a possible intrusion. CBRCOR covers using IOCs (and behavioral indicators) in detection and hunting.
Forensics
Digital Forensics is the disciplined collection and analysis of evidence from hosts, networks, and memory during an investigation. CBRCOR covers forensic techniques for incident analysis.
Chain of Custody
Chain of Custody is the documented, unbroken record of who handled evidence and when, preserving its integrity. CBRCOR covers chain of custody within incident-response and forensic processes.
Risk Scoring
Risk Scoring quantifies the severity and priority of vulnerabilities and incidents, often using CVSS and business context. CBRCOR covers risk scoring and prioritization in SOC decision-making.
CVSS
The Common Vulnerability Scoring System (CVSS) rates vulnerability severity using standardized metrics. CBRCOR covers interpreting CVSS to prioritize response and remediation.
Vulnerability Management
Vulnerability Management is the ongoing process of identifying, prioritizing, and remediating security weaknesses. CBRCOR covers vulnerability management within SOC processes.
API Integration
API Integration connects security tools so data and actions flow automatically across the SOC toolchain. CBRCOR's Automation domain covers using APIs and scripting (Python, JSON) to integrate and automate security operations.