<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="37277" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/cisco-ccnacbr" lastchanged="2026-07-24T09:20:16+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Understanding Cisco Cybersecurity Operations Fundamentals</title><productcode>CCNACBR</productcode><vendorcode>CI</vendorcode><vendorname>Cisco</vendorname><fullproductcode>CI-CCNACBR</fullproductcode><version>2.0</version><objective>&lt;ul&gt;
&lt;li&gt;Explain the foundational aspects of SOCs, including their types, key roles, and essential metrics for measuring effectiveness&lt;/li&gt;&lt;li&gt;Apply foundational security principles and risk management concepts to assess and protect organizational assets&lt;/li&gt;&lt;li&gt;Compare and apply various access control models to secure network resources and enforce organizational policies&lt;/li&gt;&lt;li&gt;Differentiate between various cloud deployment and service models and explain the shared responsibility for security in cloud environments&lt;/li&gt;&lt;li&gt;Explain the fundamental concepts of cryptography, differentiate between various cryptographic algorithms, and explain how cryptographic principles are applied in real-world protocols and systems, including key exchange, digital signatures, and SSL/TLS&lt;/li&gt;&lt;li&gt;Identify and describe the fundamental components and operational aspects of the Windows operating system for security analysis&lt;/li&gt;&lt;li&gt;Identify and describe the fundamental components and operational aspects of the Linux operating system for security analysis&lt;/li&gt;&lt;li&gt;Utilize Command Line Interfaces (CLIs) for basic system interaction, file management, and security-related tasks in both Windows and Linux environments&lt;/li&gt;&lt;li&gt;Explain the operations and identify the security implications of foundational network protocols&lt;/li&gt;&lt;li&gt;Describe and differentiate various network security controls and their application in protecting network infrastructure&lt;/li&gt;&lt;li&gt;Differentiate between various Intrusion Detection and Prevention Systems (IDS/IPS) and interpret their output for security monitoring&lt;/li&gt;&lt;li&gt;Describe and compare various endpoint security solutions and their effectiveness against common threats&lt;/li&gt;&lt;li&gt;Identify and categorize various cyber threat actors based on their motivations, capabilities, and common tactics&lt;/li&gt;&lt;li&gt;Explain the phases of the Classic Cyber Kill Chain model and identify adversary actions within each phase&lt;/li&gt;&lt;li&gt;Apply the MITRE ATT&amp;amp;CK Framework to analyze and map cyber threats, explain its structure and application, and leverage it to enhance threat detection, incident response, and communication within a security operations environment&lt;/li&gt;&lt;li&gt;Identify and describe various social engineering attack vectors, including those enhanced by generative AI&lt;/li&gt;&lt;li&gt;Describe fundamental network attack techniques that exploit protocol vulnerabilities&lt;/li&gt;&lt;li&gt;Describe advanced attack vectors and emerging threats in the current cybersecurity landscape&lt;/li&gt;&lt;li&gt;Identify and explain various types of Network Security Monitoring (NSM) data and their role in incident investigation&lt;/li&gt;&lt;li&gt;Identify and interpret various log data sources from operating systems, network devices, and security tools&lt;/li&gt;&lt;li&gt;Explain NetFlow operations and its application as a security tool for network monitoring and anomaly detection&lt;/li&gt;&lt;li&gt;Describe common web application attacks and their exploitation methods&lt;/li&gt;&lt;li&gt;Apply advanced log analysis techniques to interpret security data and identify patterns of suspicious behavior&lt;/li&gt;&lt;li&gt;Perform packet capture analysis and apply digital forensics processes to investigate security incidents. Focus on the 5-tuple and timestamps to correlate with other logs, as this is your primary tool for network forensics&lt;/li&gt;&lt;li&gt;Explain malware analysis outputs and apply threat intelligence frameworks for security investigations&lt;/li&gt;&lt;li&gt;Explain the architecture, core functions, and best practices for implementing SIEM solutions for effective security monitoring&lt;/li&gt;&lt;li&gt;Explain the features and common use cases of SOAR platforms for automating and streamlining incident response&lt;/li&gt;&lt;li&gt;Explain the Cisco XDR platform, its core functions, features, and components for unified threat detection and response&lt;/li&gt;&lt;li&gt;Differentiate between the legacy and modern NIST incident response guidance (NIST SP 800-61 Rev 2 and NIST SP 800-61 Rev 3 special publications), describe core IR components aligned with the NIST CSF 2.0 framework, and identify how these practices satisfy CMMC requirements for the Defense Industrial Base (DIB)&lt;/li&gt;&lt;li&gt;Describe the roles, categories, and operational services of Computer Security Incident Response Teams (CSIRTs)&lt;/li&gt;&lt;li&gt;Explain the concept of security monitoring playbooks and their components for standardizing incident response&lt;/li&gt;&lt;li&gt;Apply various threat hunting methodologies to proactively identify and mitigate hidden threats within a network&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;There are no formal prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Familiarity with Ethernet and TCP/IP networking&lt;/li&gt;&lt;li&gt;Working knowledge of the Windows and Linux operating systems&lt;/li&gt;&lt;li&gt;Familiarity with basics of networking security concepts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These skills can be found in the following Cisco Learning Offering:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/cisco-ccna&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Implementing and Administering Cisco Solutions &lt;span class=&quot;fl-prod-pcode&quot;&gt;(CCNA)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;Associate-Level Cybersecurity Analysts&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;ul&gt;
&lt;li&gt;Security Operations&lt;/li&gt;&lt;li&gt;Security Principles&lt;/li&gt;&lt;li&gt;Access Control Models&lt;/li&gt;&lt;li&gt;Cloud Security Models&lt;/li&gt;&lt;li&gt;Cryptography for Security Operations&lt;/li&gt;&lt;li&gt;Windows OS Basics&lt;/li&gt;&lt;li&gt;Linux OS Basics&lt;/li&gt;&lt;li&gt;CLIs in Security&lt;/li&gt;&lt;li&gt;Network Protocols&lt;/li&gt;&lt;li&gt;Network Security Controls&lt;/li&gt;&lt;li&gt;IDS and IPS&lt;/li&gt;&lt;li&gt;Endpoint Security&lt;/li&gt;&lt;li&gt;Threat Actors&lt;/li&gt;&lt;li&gt;Cyber Kill Chain Model&lt;/li&gt;&lt;li&gt;MITRE Attack Framework&lt;/li&gt;&lt;li&gt;Social Engineering Attacks&lt;/li&gt;&lt;li&gt;Network Attack Fundamentals&lt;/li&gt;&lt;li&gt;Advanced Threat Landscape&lt;/li&gt;&lt;li&gt;Network Security Monitoring (NSM) Data&lt;/li&gt;&lt;li&gt;Log Data Sources&lt;/li&gt;&lt;li&gt;NetFlow for Security Monitoring&lt;/li&gt;&lt;li&gt;Web Application Attacks&lt;/li&gt;&lt;li&gt;Advanced Log Analysis&lt;/li&gt;&lt;li&gt;Packet Capture and Forensics&lt;/li&gt;&lt;li&gt;Malware and Threat Intelligence&lt;/li&gt;&lt;li&gt;Security Information and Event Management (SIEM)&lt;/li&gt;&lt;li&gt;Security Orchestration, Automation, and Response (SOAR)&lt;/li&gt;&lt;li&gt;Extended Detection and Response (XDR)&lt;/li&gt;&lt;li&gt;Incident Response Planning&lt;/li&gt;&lt;li&gt;CSIRT Roles and Operations&lt;/li&gt;&lt;li&gt;Security Monitoring Playbooks&lt;/li&gt;&lt;li&gt;Threat Hunting Methodologies&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>- Explain the foundational aspects of SOCs, including their types, key roles, and essential metrics for measuring effectiveness
- Apply foundational security principles and risk management concepts to assess and protect organizational assets
- Compare and apply various access control models to secure network resources and enforce organizational policies
- Differentiate between various cloud deployment and service models and explain the shared responsibility for security in cloud environments
- Explain the fundamental concepts of cryptography, differentiate between various cryptographic algorithms, and explain how cryptographic principles are applied in real-world protocols and systems, including key exchange, digital signatures, and SSL/TLS
- Identify and describe the fundamental components and operational aspects of the Windows operating system for security analysis
- Identify and describe the fundamental components and operational aspects of the Linux operating system for security analysis
- Utilize Command Line Interfaces (CLIs) for basic system interaction, file management, and security-related tasks in both Windows and Linux environments
- Explain the operations and identify the security implications of foundational network protocols
- Describe and differentiate various network security controls and their application in protecting network infrastructure
- Differentiate between various Intrusion Detection and Prevention Systems (IDS/IPS) and interpret their output for security monitoring
- Describe and compare various endpoint security solutions and their effectiveness against common threats
- Identify and categorize various cyber threat actors based on their motivations, capabilities, and common tactics
- Explain the phases of the Classic Cyber Kill Chain model and identify adversary actions within each phase
- Apply the MITRE ATT&amp;CK Framework to analyze and map cyber threats, explain its structure and application, and leverage it to enhance threat detection, incident response, and communication within a security operations environment
- Identify and describe various social engineering attack vectors, including those enhanced by generative AI
- Describe fundamental network attack techniques that exploit protocol vulnerabilities
- Describe advanced attack vectors and emerging threats in the current cybersecurity landscape
- Identify and explain various types of Network Security Monitoring (NSM) data and their role in incident investigation
- Identify and interpret various log data sources from operating systems, network devices, and security tools
- Explain NetFlow operations and its application as a security tool for network monitoring and anomaly detection
- Describe common web application attacks and their exploitation methods
- Apply advanced log analysis techniques to interpret security data and identify patterns of suspicious behavior
- Perform packet capture analysis and apply digital forensics processes to investigate security incidents. Focus on the 5-tuple and timestamps to correlate with other logs, as this is your primary tool for network forensics
- Explain malware analysis outputs and apply threat intelligence frameworks for security investigations
- Explain the architecture, core functions, and best practices for implementing SIEM solutions for effective security monitoring
- Explain the features and common use cases of SOAR platforms for automating and streamlining incident response
- Explain the Cisco XDR platform, its core functions, features, and components for unified threat detection and response
- Differentiate between the legacy and modern NIST incident response guidance (NIST SP 800-61 Rev 2 and NIST SP 800-61 Rev 3 special publications), describe core IR components aligned with the NIST CSF 2.0 framework, and identify how these practices satisfy CMMC requirements for the Defense Industrial Base (DIB)
- Describe the roles, categories, and operational services of Computer Security Incident Response Teams (CSIRTs)
- Explain the concept of security monitoring playbooks and their components for standardizing incident response
- Apply various threat hunting methodologies to proactively identify and mitigate hidden threats within a network</objective_plain><essentials_plain>There are no formal prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:


- Familiarity with Ethernet and TCP/IP networking
- Working knowledge of the Windows and Linux operating systems
- Familiarity with basics of networking security concepts
These skills can be found in the following Cisco Learning Offering:


- Implementing and Administering Cisco Solutions (CCNA)</essentials_plain><audience_plain>- Associate-Level Cybersecurity Analysts</audience_plain><outline_plain>- Security Operations
- Security Principles
- Access Control Models
- Cloud Security Models
- Cryptography for Security Operations
- Windows OS Basics
- Linux OS Basics
- CLIs in Security
- Network Protocols
- Network Security Controls
- IDS and IPS
- Endpoint Security
- Threat Actors
- Cyber Kill Chain Model
- MITRE Attack Framework
- Social Engineering Attacks
- Network Attack Fundamentals
- Advanced Threat Landscape
- Network Security Monitoring (NSM) Data
- Log Data Sources
- NetFlow for Security Monitoring
- Web Application Attacks
- Advanced Log Analysis
- Packet Capture and Forensics
- Malware and Threat Intelligence
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation, and Response (SOAR)
- Extended Detection and Response (XDR)
- Incident Response Planning
- CSIRT Roles and Operations
- Security Monitoring Playbooks
- Threat Hunting Methodologies</outline_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="GB" currency="GBP">3305.00</price><price country="IT" currency="EUR">3290.00</price><price country="DE" currency="EUR">4495.00</price><price country="FR" currency="EUR">4170.00</price><price country="CH" currency="CHF">4495.00</price><price country="AT" currency="EUR">4495.00</price><price country="SE" currency="EUR">4495.00</price><price country="SI" currency="EUR">4495.00</price></pricelist><miles><milesvalue country="GB" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">44.00</milesvalue></miles></course>