ASSA80 logo
Focused certification exam prep
Start practice

ASSA80 Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • Exam 250-552 has 65-75 questions, a 90-minute limit, and a 70% passing score.
  • The exam fee is USD 250, delivered in English via Pearson VUE test centers or OnVUE remote proctoring.
  • Ten objective domains cover capture, architecture, deployment, filtering, extraction, IoCs, threat hunting, reporting, and integrations.
  • Broadcom recommends three months of hands-on experience; the BTS study guide suggests 3-6 months.

Exam Snapshot: The Numbers You Must Memorize

If you only have five minutes before closing this tab, memorize these figures. They come straight from the official Broadcom exam listing for 250-552, Symantec Security Analytics 8.0 Technical Specialist, part of the Broadcom Technical Specialist (BTS) program.

  • Question count: 65-75 questions per attempt.
  • Time limit: 90 minutes.
  • Passing score: 70%.
  • Delivery language: English.
  • Exam fee: USD 250.
  • Format: Closed book, proctored, with single-answer and multiple-response question types.

You also must accept the Broadcom Software Certification Agreement before your result is finalized. For a full breakdown of what that 70% threshold actually means in raw question terms, see ASSA80 Passing Score 2026: Exactly What You Need to Pass. And if you want the full pricing picture including any add-ons or retake considerations, check ASSA80 Certification Cost 2026: Complete Pricing Breakdown.

Experience Baseline: The exam page recommends three months of regular production or laboratory experience with intermediate networking and security knowledge. The BTS study guide widens that to 3-6 months. Either way, this is not a certification you should attempt cold from reading alone.

The Ten Domains at a Glance

The BTS study guide organizes 250-552 into ten objective domains. Every question on the exam maps back to one of these. Treat this list as your master checklist - if you can't explain each bullet out loud, that's your next study session.

Domain 1: Network Traffic Capture and Visibility

Describe how Security Analytics provides visibility by capturing network traffic as it traverses the network.

  • Understand what "full packet capture" visibility actually gives an analyst versus flow-only tools.

Domain 2: Core Architecture

Describe the core architecture of Security Analytics, including virtual and hardware appliances.

  • Know the difference between deployment options and how appliance type affects capacity planning.

Domain 3: Network Architecture Requirements

Describe the Symantec Security Analytics network architecture requirements, including the differences between network TAPs and SPAN ports.

  • This is the domain most candidates underestimate - see the dedicated comparison below.

Domain 4: Deployment Configuration

Describe how to configure Security Analytics deployment, including key options within both the CLI and web interface.

  • Expect scenario questions asking which interface (CLI vs GUI) is appropriate for a given configuration task.

Domain 5: Filtering and Indicators

Describe how to perform basic and advanced filtering, create indicators, and apply recommended filtering best practices.

  • Practice reading filter syntax and predicting the resulting result set.

Domain 6: File Extraction

Describe the file extraction process, the resulting artifacts, and the purposes they serve.

  • Know what artifact types are produced and how analysts use them downstream in an investigation.

Domain 7: Cyber-Attack Anatomy and IoCs

Describe the anatomy of a cyber-attack, the steps of the Cyber Kill Chain, and what makes up an Indicator of Compromise (IoC).

  • Be able to sequence Kill Chain stages and match them to Security Analytics evidence types.

Domain 8: Threat Hunting and Incident Response

Describe threat hunting and incident response frameworks and procedures.

  • Connect retrospective investigation capability to a hunt workflow, not just a static definition.

Domain 9: Reporting

Describe how to create, use, and distribute reports in Security Analytics.

  • Know the difference between generating a report for internal review versus distributing it to stakeholders.

Domain 10: Integrations

Describe how Security Analytics integrates with both Symantec and third-party security products.

  • Understand why integrations matter for a platform whose core value is packet-level evidence feeding other tools.

For a much deeper walkthrough of each objective with worked examples, read ASSA80 Exam Domains 2026: Complete Guide to All 10 Content Areas. If you're still deciding how much runway you need before sitting the exam, How Hard Is the ASSA80 Exam? Complete Difficulty Guide 2026 breaks down where most candidates lose time.

Network TAP vs SPAN Port: The One Comparison You Can't Skip

Domain 3 explicitly calls out the differences between network TAPs and SPAN ports, and this comparison shows up repeatedly across scenario-style questions on 250-552. Memorize the operational distinctions, not just the definitions.

AspectNetwork TAPSPAN Port
PlacementDedicated hardware inline on the linkConfigured feature on an existing switch
Traffic FidelityPassive copy, no packet drops under loadCan drop packets if switch is oversubscribed
DependencyIndependent of switch CPU/resourcesShares switch processing resources
Common Use in Security AnalyticsPreferred for guaranteed full-fidelity captureAcceptable when TAP hardware isn't available

Key Takeaway

When a scenario question describes packet loss or resource contention on the capture side, think SPAN port limitations. When it describes guaranteed full-fidelity visibility for forensic-grade investigations, think TAP.

Filtering, File Extraction, and Threat Hunting Fast Facts

Beyond capture and architecture, the exam leans heavily on what happens once traffic is captured. This cluster of domains - filtering, file extraction, and threat hunting - represents the day-to-day analyst workflow that Security Analytics is built to support.

Filtering (Domain 5)

  • Distinguish basic filters from advanced filters and know when each is appropriate.
  • Understand how indicators are created and applied to narrow an investigation.
  • Recommended filtering best practices are testable - don't skip the "why," only memorize the "how."

File Extraction (Domain 6)

  • Know the extraction process end to end: from capture, to identification, to artifact output.
  • Understand the purpose each artifact type serves for an analyst reconstructing an incident.

Threat Hunting and IoCs (Domains 7-8)

  • Be fluent in the Cyber Kill Chain stages and how retrospective investigation ties evidence back to each stage.
  • Know what constitutes an Indicator of Compromise in the context of packet-level evidence, not just endpoint logs.
Why This Matters for Employers: Security Analytics is a network forensics and retrospective investigation platform. Roles that value this certification typically involve SOC analysis, incident response, and network threat hunting - see ASSA80 Jobs for how this maps to real hiring language, and ASSA80 Salary Guide 2026: Complete Earnings Analysis for how the skill set is positioned in the market.

Registration, Delivery, and Recertification Mechanics

The administrative side of 250-552 trips up candidates who assume it works like other vendor exams. Here's what's actually confirmed:

  • Registration system: CertMetrics, paired with Pearson VUE for scheduling.
  • Delivery options: Pearson VUE test centers or OnVUE remote proctoring.
  • Testing conditions: Closed book, proctored.
  • Certification validity: Two years under the BTS program.
  • Recertification: Pass an available Broadcom Software exam version before expiration.

Note also that Security Analytics maintenance and technical support are scheduled to end November 1, 2030 - this is a product-support lifecycle milestone, not an exam retirement date, so don't conflate the two when planning your certification timeline. For the full eligibility picture including the experience recommendations and agreement requirement, see ASSA80 Requirements 2026: Eligibility, Prerequisites & How to Qualify, and for scheduling windows check ASSA80 Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Key Takeaway

Register through CertMetrics, schedule through Pearson VUE, and pick OnVUE only if your testing environment can meet remote-proctoring requirements - otherwise a test center avoids last-minute technical issues.

8.0 Exam Title vs 8.2.5 Training: Don't Get Confused

One detail that quietly derails preparation: the exam is titled Symantec Security Analytics 8.0 Technical Specialist, and the study guide references 8.0.x documentation - but the official exam page recommends Security Analytics 8.2.5 Administration training as preparation. This is not a mismatch or a new exam; it simply means the recommended training material has moved ahead in version number while the exam name and objective mapping stay tied to 8.0.

Practical guidance: when you work through practice scenarios or lab exercises, match them to the ten exam objectives listed above rather than treating the 8.2.5 training version as a separate credential or assuming content has been renamed. The objectives - capture, architecture, deployment, filtering, extraction, Kill Chain/IoCs, threat hunting, reporting, integrations - are your anchor regardless of which documentation version you're reading.

Version Note: If your study materials reference 8.2.5 screenshots or menu paths that differ slightly from what you expect, don't panic - align what you're seeing to the objective it demonstrates, not to a specific build number.

A Compressed Final-Week Review Plan

If you're within a week of your exam date, spend your remaining hours on the domains most likely to appear as multi-part or scenario questions rather than re-reading definitions you already know.

Days 1-2

Architecture and Network Fundamentals

  • Re-drill Domain 2 (core architecture) and Domain 3 (TAP vs SPAN) using the comparison table above.
  • Write out, from memory, why fidelity differs between capture methods.
Days 3-4

Deployment, Filtering, Extraction

  • Walk through CLI vs web interface deployment scenarios (Domain 4).
  • Practice predicting filter output and reviewing extraction artifact purposes (Domains 5-6).
Days 5-6

Investigation Logic

  • Sequence Cyber Kill Chain stages and map IoC types to them (Domain 7).
  • Review threat hunting and incident response procedures (Domain 8), then reporting and distribution options (Domain 9).
Day 7

Integrations and Full Mock Run

  • Finish with Domain 10 integrations, then take a full-length timed practice run at ../ to simulate the 90-minute limit.

For a more complete week-by-week plan built from day one rather than a final cram, see ASSA80 Study Guide 2026: How to Pass on Your First Attempt. And if you're weighing whether the credential is worth the prep time and USD 250 fee at all, Is the ASSA80 Certification Worth It? Complete ROI Analysis 2026 lays out the ROI case.

Before test day, run a handful of full-length timed sets on the main practice test platform so the 65-75 question, 90-minute pacing feels routine rather than a surprise. Repeating this on practice sessions a few times in the final week builds the pacing instinct that raw reading never will.

FAQ

How many questions are on the ASSA80 (250-552) exam?

The official exam listing specifies 65-75 questions, delivered within a 90-minute time limit, with a required passing score of 70%.

What does the ASSA80 exam actually cost?

The official fee listed for exam 250-552 is USD 250. See ASSA80 Certification Cost 2026: Complete Pricing Breakdown for the full picture.

Why does the exam page recommend 8.2.5 training for an exam titled 8.0?

The exam remains titled Symantec Security Analytics 8.0 Technical Specialist and the study guide references 8.0.x documentation, while Broadcom currently recommends Security Analytics 8.2.5 Administration training as preparation. Match your study to the ten exam objectives rather than the training version number.

How long is the certification valid, and how do I renew it?

BTS certification is valid for two years. Recertification requires passing an available Broadcom Software exam version before that window closes.

Does the 2030 support end date mean the exam will retire?

No. Security Analytics maintenance and technical support are scheduled to end November 1, 2030, but that is a product-support lifecycle notice, not a statement about exam retirement.

Ready to pass your ASSA80 exam?

Put this into practice with free ASSA80 questions across every exam domain.