A two-exam security operations credential covering advanced detection and response plus digital forensics and incident response.
CyberOps Professional requires the 350-201 CBRCOR core exam and the 300-215 CBRFIR concentration exam. Together they cover the full incident lifecycle: detection engineering, hunting, response and forensic analysis.
The credential sits above CyberOps Associate and is aimed at analysts who already work incidents rather than triage alerts.
Automation appears throughout both exams, reflecting how much modern SOC work is playbook-driven rather than manual.
In the order most candidates take them. Where a track offers a choice of concentration, every eligible exam is listed.
The CyberOps Professional core exam: security fundamentals at depth, detection and hunting techniques, incident response processes, and automating security operations.
The forensics concentration for CyberOps Professional: evidence handling, forensic techniques across hosts and networks, and structured incident response processes.
Cisco CyberOps Professional requires 2 exams. They are listed below in the order most candidates take them.
36 months from the date the final exam is passed. Renewal requirements are set by the vendor and change from time to time, so confirm before your expiry date.
Tracks that build on this one, or that pair well with it.
Professional-level Cisco security: the SCOR core exam plus one concentration covering firewalls, identity services, email security or VPNs.
Cisco