Course ID: #CBROPS

CBROPS – Understanding Cisco Cybersecurity Operations Fundamentals

Duration: 5 days Dates: 16 November 2026 22 February 2027 24 May 2027 23 August 2027

The entry point into working in a Security Operations Center, and the basis for the CCNA Cybersecurity certification that Cisco created from CyberOps Associate in early 2026. You get to know security concepts, monitoring and attack patterns, analyse endpoints and network traffic, read PCAP files with Wireshark, and work with the incident response process per NIST SP 800-61. Note: the 200-201 exam is only available in English; the course is held in German.

Security Concepts

  • The CIA triad and its relevance in everyday work
  • Comparing security deployments and terminology
  • Defense in depth as a strategy
  • Comparing access control models
  • Correctly reading CVSS terminology
  • Recognising visibility gaps in network, host and cloud
  • Inferring data exfiltration from traffic profiles
  • The 5-tuple approach to scoping a compromised host
  • Rule-based versus behavioural and statistical detection

Security Monitoring

  • Distinguishing between attack surface and vulnerability
  • Which technologies deliver which data, and how they affect visibility
  • Network attacks: protocol-based, denial of service, distributed denial of service, man-in-the-middle
  • Attacks on web applications: SQL injection, command injection, cross-site scripting
  • Social engineering, including with generative AI
  • Attacks on endpoints: buffer overflow, command and control, malware, ransomware
  • Obfuscation techniques: tunnelling, encryption, proxies
  • Certificates and PKI in a security context

Host-Based Analysis

  • Endpoint technologies in security monitoring, with rules, signatures and predictive AI
  • Identifying components of Windows and Linux systems
  • The role of attribution in an investigation
  • Determining evidence types from the logs available
  • Evaluating logs from operating system, SIEM, SOAR and command line
  • Interpreting reports from malware analysis tools and sandboxes

Network Intrusion Analysis

  • Mapping events to their source technologies
  • Deep packet inspection versus packet filters and stateful firewalls
  • Inline interrogation versus taps and traffic monitoring
  • Data from taps versus transaction data from NetFlow
  • Extracting files from a TCP stream with Wireshark
  • Recognising key elements of an attack in a PCAP file
  • Reading protocol headers for intrusion analysis
  • Regular expressions in practice

Security Policies and Procedures

  • Management concepts overview
  • The incident response plan per NIST SP 800-61
  • Applying the incident handling process to an event
  • Mapping stakeholders to NIST IR categories
  • Forensics fundamentals per NIST SP 800-86
  • Network and server profiling
  • Identifying data worth protecting on the network
  • Classifying events per the Cyber Kill Chain and Diamond Model
  • SOC metrics: time to detection, containment and response
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar, Prüfungsvorbereitung

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/11/16, 2027/02/22, 2027/05/24, 2027/08/23, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, flexibel, auf Anfrage

Newcomers to security operations, first- and second-level support staff, system administrators with security responsibilities, and anyone looking to move into a SOC team. Basic knowledge of networking and of working with Windows and Linux is required.

  • Confidently classify security concepts and the CIA triad
  • Recognise attack types against networks, web applications and endpoints
  • Evaluate monitoring data sources and identify visibility gaps
  • Evaluate operating system, SIEM and command-line logs
  • Analyse network traffic, evaluate PCAP files with Wireshark
  • Classify events per the Cyber Kill Chain and Diamond Model
  • Apply the incident response process per NIST SP 800-61
  • Be prepared for the 200-201 exam

Price range: CHF3'400 through CHF15'600 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation