Cisco Certified CyberOps Associate (200-201) Cert Prep: 2 Security Monitoring

Brought by: LinkedIn Learning

Overview

Explore the principles of defense in depth as you prepare for the Security Monitoring portion of the Cisco Cybersecurity Operations Fundamentals (CBROPS) exam.

Syllabus

Introduction
  • Active security monitoring
  • Prepare for Cisco CBROPS exam
  • Setting up your test environment
1. Understanding Attacks
  • Recognizing attack surfaces
  • Identifying vulnerability testing
  • Attacking the network
  • Describing web application attacks
  • Hacking the human
  • Investigating endpoint-based attacks
  • Challenge: Research and identify social engineering attacks
  • Solution: Research and identify social engineering attacks
2. Examining System Data
  • Exploring CLI tools
  • Analyzing data with NetFlow
  • Monitoring traffic with a stateful firewall
  • Deploying a next-generation firewall
  • Having application visibility and control
  • Filtering web and email content
  • Challenge: Using NetFlow in Packet Tracer
  • Solution: Using NetFlow in Packet Tracer
3. Comparing Data Types Used in Security Monitoring
  • Obtaining a packet capture with Wireshark
  • Understanding conversations and endpoints
  • Visualizing session and transactional data
  • Analyzing statistical data
  • Sending alert data
  • Investigating an IDS alert
  • Challenge: Using Wireshark to examine DNS traffic
  • Solution: Using Wireshark to examine DNS traffic
4. Limiting Data Visibility
  • Using an access control list
  • Concealing the network using NAT/PAT
  • Evading and hiding techniques
  • Tunneling and encapsulation
  • Using encryption to hide
5. Using Certificates
  • Protecting data and networks
  • Ensuring trust on the Internet
  • Examining an X.509 certificate
  • Describing certificate classes
  • Grasping the public key cryptography standards (PKCS)
  • Managing keys using IKE
  • Outlining the different protocol versions
  • Configuring the cipher suite
  • Challenge: Certificate Authority Stores
  • Solution: Certificate Authority Stores
Conclusion
  • Next steps

Taught by

Lisa Bock

Cisco Certified CyberOps Associate (200-201) Cert Prep: 2 Security Monitoring
Go to course

Cisco Certified CyberOps Associate (200-201) Cert Prep: 2 Security Monitoring

Brought by: LinkedIn Learning

  • LinkedIn Learning
  • Paid
  • English
  • Certificate Available
  • Available at any time
  • All
  • N/A
8.1.2PHP Version276msRequest Duration2MBMemory UsageGET en/courses/{slug}Route
    • Booting (161ms)
    • Application (114ms)
    • 1 x Booting (58.5%)
      161.17ms
      1 x Application (41.26%)
      113.69ms
      14 templates were rendered
      • public.courses.show (resources/views/public/courses/show.blade.php)3bladefile
        Params
        0
        course
        1
        links
        2
        config
      • public.courses.partials.breadcrumbs (resources/views/public/courses/partials/breadcrumbs.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.courses.partials.heading (resources/views/public/courses/partials/heading.blade.php)7bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
        6
        classes
      • public.courses.partials.details (resources/views/public/courses/partials/details.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.courses.partials.breadcrumbs (resources/views/public/courses/partials/breadcrumbs.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.courses.partials.heading (resources/views/public/courses/partials/heading.blade.php)7bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
        6
        classes
      • public.layouts.main (resources/views/public/layouts/main.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.layouts.partials.meta (resources/views/public/layouts/partials/meta.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.layouts.partials.navbar (resources/views/public/layouts/partials/navbar.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.auth.profile.partials.links (resources/views/public/auth/profile/partials/links.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      • public.auth.profile.partials.link (resources/views/public/auth/profile/partials/link.blade.php)8bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
        6
        route
        7
        title
      • public.auth.profile.partials.link (resources/views/public/auth/profile/partials/link.blade.php)8bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
        6
        route
        7
        title
      • public.auth.profile.partials.link (resources/views/public/auth/profile/partials/link.blade.php)8bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
        6
        route
        7
        title
      • public.layouts.partials.flash-session (resources/views/public/layouts/partials/flash-session.blade.php)6bladefile
        Params
        0
        __env
        1
        app
        2
        errors
        3
        course
        4
        links
        5
        config
      uri
      GET en/courses/{slug}
      middleware
      web, localize:en
      controller
      App\Http\Controllers\CourseController@show
      as
      en.courses.show
      namespace
      prefix
      /en
      where
      file
      app/Http/Controllers/CourseController.php:17-35
      6 statements were executed17.98ms
      • select * from `courses` where `slug_en` = 'cisco-certified-cyberops-associate-(200-201)-cert-prep:-2-security-monitoring' limit 1
        16.35ms/app/Http/Controllers/CourseController.php:20corspedia
        Metadata
        Bindings
        • 0. cisco-certified-cyberops-associate-(200-201)-cert-prep:-2-security-monitoring
        Backtrace
        • 17. /app/Http/Controllers/CourseController.php:20
        • 18. /vendor/laravel/framework/src/Illuminate/Routing/Controller.php:54
        • 19. /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php:43
        • 20. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:260
        • 21. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:205
      • update `courses` set `visitors` = `visitors` + 1, `courses`.`updated_at` = '2025-05-23 12:51:29' where `id` = 5643
        700μs/app/Http/Controllers/CourseController.php:21corspedia
        Metadata
        Bindings
        • 0. 2025-05-23 12:51:29
        • 1. 5643
        Backtrace
        • 17. /app/Http/Controllers/CourseController.php:21
        • 18. /vendor/laravel/framework/src/Illuminate/Routing/Controller.php:54
        • 19. /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php:43
        • 20. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:260
        • 21. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:205
      • select `id`, `name_en`, `name_ar`, `topic_id`, `slug_en`, `slug_ar` from `subjects` where `subjects`.`id` in (72)
        240μs/app/Http/Controllers/CourseController.php:23corspedia
        Metadata
        Backtrace
        • 20. /app/Http/Controllers/CourseController.php:23
        • 21. /vendor/laravel/framework/src/Illuminate/Routing/Controller.php:54
        • 22. /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php:43
        • 23. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:260
        • 24. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:205
      • select `id`, `name_en`, `name_ar`, `slug_en`, `slug_ar` from `topics` where `topics`.`id` in (1)
        210μs/app/Http/Controllers/CourseController.php:23corspedia
        Metadata
        Backtrace
        • 25. /app/Http/Controllers/CourseController.php:23
        • 26. /vendor/laravel/framework/src/Illuminate/Routing/Controller.php:54
        • 27. /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php:43
        • 28. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:260
        • 29. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:205
      • select * from `providers` where `providers`.`id` in (56) and `providers`.`deleted_at` is null
        240μs/app/Http/Controllers/CourseController.php:23corspedia
        Metadata
        Backtrace
        • 20. /app/Http/Controllers/CourseController.php:23
        • 21. /vendor/laravel/framework/src/Illuminate/Routing/Controller.php:54
        • 22. /vendor/laravel/framework/src/Illuminate/Routing/ControllerDispatcher.php:43
        • 23. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:260
        • 24. /vendor/laravel/framework/src/Illuminate/Routing/Route.php:205
      • select * from `html_files` where `html_files`.`id` = 5634 limit 1
        240μs/app/Models/Course.php:84corspedia
        Metadata
        Bindings
        • 0. 5634
        Backtrace
        • 21. /app/Models/Course.php:84
        • 28. view::public.courses.show:29
        • 30. /vendor/laravel/framework/src/Illuminate/Filesystem/Filesystem.php:125
        • 31. /vendor/laravel/framework/src/Illuminate/View/Engines/PhpEngine.php:58
        • 32. /vendor/laravel/framework/src/Illuminate/View/Engines/CompilerEngine.php:72
      App\Models\HtmlFile
      1
      App\Models\Provider
      1
      App\Models\Topic
      1
      App\Models\Subject
      1
      App\Models\Course
      1
        _token
        2aQJYU4YcTqDNkYSNJUOj1J0sEyCo39bE3O344Kn
        locale
        en
        _previous
        array:1 [ "url" => "https://www.corspedia.com/en/courses/cisco-certified-cyberops-associate-%28200...
        _flash
        array:2 [ "old" => [] "new" => [] ]
        PHPDEBUGBAR_STACK_DATA
        []
        path_info
        /en/courses/cisco-certified-cyberops-associate-%28200-201%29-cert-prep:-2-security-monitoring
        status_code
        200
        
        status_text
        OK
        format
        html
        content_type
        text/html; charset=UTF-8
        request_query
        []
        
        request_request
        []
        
        request_headers
        0 of 0
        array:24 [ "cf-ipcountry" => array:1 [ 0 => "US" ] "cf-connecting-ip" => array:1 [ 0 => "3.145.108.4" ] "cdn-loop" => array:1 [ 0 => "cloudflare; loops=1" ] "x-forwarded-proto" => array:1 [ 0 => "https" ] "x-forwarded-for" => array:1 [ 0 => "3.145.108.4" ] "sec-fetch-site" => array:1 [ 0 => "none" ] "accept" => array:1 [ 0 => "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" ] "user-agent" => array:1 [ 0 => "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" ] "upgrade-insecure-requests" => array:1 [ 0 => "1" ] "sec-ch-ua-platform" => array:1 [ 0 => ""Windows"" ] "sec-ch-ua-mobile" => array:1 [ 0 => "?0" ] "sec-ch-ua" => array:1 [ 0 => ""Chromium";v="130", "HeadlessChrome";v="130", "Not?A_Brand";v="99"" ] "cache-control" => array:1 [ 0 => "no-cache" ] "pragma" => array:1 [ 0 => "no-cache" ] "sec-fetch-dest" => array:1 [ 0 => "document" ] "cf-ray" => array:1 [ 0 => "9444af582c23e12f-ORD" ] "accept-encoding" => array:1 [ 0 => "gzip, br" ] "priority" => array:1 [ 0 => "u=0, i" ] "sec-fetch-user" => array:1 [ 0 => "?1" ] "sec-fetch-mode" => array:1 [ 0 => "navigate" ] "cf-visitor" => array:1 [ 0 => "{"scheme":"https"}" ] "host" => array:1 [ 0 => "www.corspedia.com" ] "content-length" => array:1 [ 0 => "" ] "content-type" => array:1 [ 0 => "" ] ]
        request_server
        0 of 0
        array:50 [ "USER" => "www-data" "HOME" => "/var/www" "HTTP_CF_IPCOUNTRY" => "US" "HTTP_CF_CONNECTING_IP" => "3.145.108.4" "HTTP_CDN_LOOP" => "cloudflare; loops=1" "HTTP_X_FORWARDED_PROTO" => "https" "HTTP_X_FORWARDED_FOR" => "3.145.108.4" "HTTP_SEC_FETCH_SITE" => "none" "HTTP_ACCEPT" => "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" "HTTP_USER_AGENT" => "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" "HTTP_UPGRADE_INSECURE_REQUESTS" => "1" "HTTP_SEC_CH_UA_PLATFORM" => ""Windows"" "HTTP_SEC_CH_UA_MOBILE" => "?0" "HTTP_SEC_CH_UA" => ""Chromium";v="130", "HeadlessChrome";v="130", "Not?A_Brand";v="99"" "HTTP_CACHE_CONTROL" => "no-cache" "HTTP_PRAGMA" => "no-cache" "HTTP_SEC_FETCH_DEST" => "document" "HTTP_CF_RAY" => "9444af582c23e12f-ORD" "HTTP_ACCEPT_ENCODING" => "gzip, br" "HTTP_PRIORITY" => "u=0, i" "HTTP_SEC_FETCH_USER" => "?1" "HTTP_SEC_FETCH_MODE" => "navigate" "HTTP_CF_VISITOR" => "{"scheme":"https"}" "HTTP_HOST" => "www.corspedia.com" "REDIRECT_STATUS" => "200" "SERVER_NAME" => "corspedia.com" "SERVER_PORT" => "443" "SERVER_ADDR" => "141.95.147.152" "REMOTE_USER" => "" "REMOTE_PORT" => "40162" "REMOTE_ADDR" => "172.70.126.208" "SERVER_SOFTWARE" => "nginx/1.18.0" "GATEWAY_INTERFACE" => "CGI/1.1" "HTTPS" => "on" "REQUEST_SCHEME" => "https" "SERVER_PROTOCOL" => "HTTP/2.0" "DOCUMENT_ROOT" => "/var/www/corspedia/public" "DOCUMENT_URI" => "/index.php" "REQUEST_URI" => "/en/courses/cisco-certified-cyberops-associate-%28200-201%29-cert-prep:-2-security-monitoring" "SCRIPT_NAME" => "/index.php" "CONTENT_LENGTH" => "" "CONTENT_TYPE" => "" "REQUEST_METHOD" => "GET" "QUERY_STRING" => "" "SCRIPT_FILENAME" => "/var/www/corspedia/public/index.php" "PATH_INFO" => "" "FCGI_ROLE" => "RESPONDER" "PHP_SELF" => "/index.php" "REQUEST_TIME_FLOAT" => 1748004688.9341 "REQUEST_TIME" => 1748004688 ]
        request_cookies
        []
        
        response_headers
        0 of 0
        array:5 [ "content-type" => array:1 [ 0 => "text/html; charset=UTF-8" ] "cache-control" => array:1 [ 0 => "no-cache, private" ] "date" => array:1 [ 0 => "Fri, 23 May 2025 12:51:29 GMT" ] "set-cookie" => array:2 [ 0 => "XSRF-TOKEN=eyJpdiI6ImxISkd6dkJHbEN6cEVGOGxWRXRJc1E9PSIsInZhbHVlIjoibkdKaFN4aFE3am5WcWJGZlNjUWNBdTNsV3VLbERXRVdHYzBuZVpCRWppTXQ1OENVRFN6dURKVUtubnh0T3NrYmhGUjFSTU80RldQOEx1WHgrQ0NFV1Eza0JVWGFaYXBER1pqSk4yWXE3TGZzS3pSNDJ3WlpJVzlOdUYwSC8zbXUiLCJtYWMiOiJhYmQ5NmY1ZWJmMjEwZGM4NmVkYmQxNzU2MWQyOWY1NGQ1YjZmMGMxZjM3OWUyODM0MjI4NmI3MDBkOGQ1MDUyIiwidGFnIjoiIn0%3D; expires=Fri, 23 May 2025 14:51:29 GMT; Max-Age=7200; path=/; samesite=laxXSRF-TOKEN=eyJpdiI6ImxISkd6dkJHbEN6cEVGOGxWRXRJc1E9PSIsInZhbHVlIjoibkdKaFN4aFE3am5WcWJGZlNjUWNBdTNsV3VLbERXRVdHYzBuZVpCRWppTXQ1OENVRFN6dURKVUtubnh0T3NrYmhGUjFST" 1 => "laravel_session=eyJpdiI6InQrSGZFODFGanBFWHpMeGdPamFTSXc9PSIsInZhbHVlIjoiZmRIT3hpSXVFTEVSNFZWbG5nTHVWT1hQWmxCbEVvd2VubXZTV29ZTzR6T1dCRzlJSlBZTUt6T1VUYXZGbFIvUG5ydVhPcEhaYU9JbjhidDFINWdxMTF2dU51REpzeUlFZ1I4bzR3dDB2WlY0YnFPYXVpNTU4MWlHOWNaV0dNMnIiLCJtYWMiOiJhNDE5ZDc3YmZkNWQ0ODFjYWRiMjc5ZTRiZTJkZTAzNjFhZDg0YTc2YjJlMjc0MTg5ZmYwNTk4MTUzMGZkZDI0IiwidGFnIjoiIn0%3D; expires=Fri, 23 May 2025 14:51:29 GMT; Max-Age=7200; path=/; httponly; samesite=laxlaravel_session=eyJpdiI6InQrSGZFODFGanBFWHpMeGdPamFTSXc9PSIsInZhbHVlIjoiZmRIT3hpSXVFTEVSNFZWbG5nTHVWT1hQWmxCbEVvd2VubXZTV29ZTzR6T1dCRzlJSlBZTUt6T1VUYXZGbFIvUG5y" ] "Set-Cookie" => array:2 [ 0 => "XSRF-TOKEN=eyJpdiI6ImxISkd6dkJHbEN6cEVGOGxWRXRJc1E9PSIsInZhbHVlIjoibkdKaFN4aFE3am5WcWJGZlNjUWNBdTNsV3VLbERXRVdHYzBuZVpCRWppTXQ1OENVRFN6dURKVUtubnh0T3NrYmhGUjFSTU80RldQOEx1WHgrQ0NFV1Eza0JVWGFaYXBER1pqSk4yWXE3TGZzS3pSNDJ3WlpJVzlOdUYwSC8zbXUiLCJtYWMiOiJhYmQ5NmY1ZWJmMjEwZGM4NmVkYmQxNzU2MWQyOWY1NGQ1YjZmMGMxZjM3OWUyODM0MjI4NmI3MDBkOGQ1MDUyIiwidGFnIjoiIn0%3D; expires=Fri, 23-May-2025 14:51:29 GMT; path=/XSRF-TOKEN=eyJpdiI6ImxISkd6dkJHbEN6cEVGOGxWRXRJc1E9PSIsInZhbHVlIjoibkdKaFN4aFE3am5WcWJGZlNjUWNBdTNsV3VLbERXRVdHYzBuZVpCRWppTXQ1OENVRFN6dURKVUtubnh0T3NrYmhGUjFST" 1 => "laravel_session=eyJpdiI6InQrSGZFODFGanBFWHpMeGdPamFTSXc9PSIsInZhbHVlIjoiZmRIT3hpSXVFTEVSNFZWbG5nTHVWT1hQWmxCbEVvd2VubXZTV29ZTzR6T1dCRzlJSlBZTUt6T1VUYXZGbFIvUG5ydVhPcEhaYU9JbjhidDFINWdxMTF2dU51REpzeUlFZ1I4bzR3dDB2WlY0YnFPYXVpNTU4MWlHOWNaV0dNMnIiLCJtYWMiOiJhNDE5ZDc3YmZkNWQ0ODFjYWRiMjc5ZTRiZTJkZTAzNjFhZDg0YTc2YjJlMjc0MTg5ZmYwNTk4MTUzMGZkZDI0IiwidGFnIjoiIn0%3D; expires=Fri, 23-May-2025 14:51:29 GMT; path=/; httponlylaravel_session=eyJpdiI6InQrSGZFODFGanBFWHpMeGdPamFTSXc9PSIsInZhbHVlIjoiZmRIT3hpSXVFTEVSNFZWbG5nTHVWT1hQWmxCbEVvd2VubXZTV29ZTzR6T1dCRzlJSlBZTUt6T1VUYXZGbFIvUG5y" ] ]
        session_attributes
        0 of 0
        array:5 [ "_token" => "2aQJYU4YcTqDNkYSNJUOj1J0sEyCo39bE3O344Kn" "locale" => "en" "_previous" => array:1 [ "url" => "https://www.corspedia.com/en/courses/cisco-certified-cyberops-associate-%28200-201%29-cert-prep:-2-security-monitoring" ] "_flash" => array:2 [ "old" => [] "new" => [] ] "PHPDEBUGBAR_STACK_DATA" => [] ]