ASSA80 logo
Focused certification exam prep
Start practice

ASSA80 Exam Domains 2026: Complete Guide to All 10 Content Areas

TL;DR
  • ASSA80 (exam 250-552) is organized into exactly ten domains defined in Broadcom's BTS study guide.
  • The exam has 65-75 questions, a 90-minute limit, and a 70% passing score.
  • Domains 5, 6, 7, and 8 (filtering, extraction, kill chain, threat hunting) carry the heaviest practical weight.
  • Broadcom recommends Security Analytics 8.2.5 Administration training even though the exam is titled 8.0.

Exam Overview: What the 250-552 Actually Tests

Administration of Symantec Security Analytics 8.0, commonly shortened to ASSA80, is the certification associated with Broadcom's exam 250-552, officially named Symantec Security Analytics 8.0 Technical Specialist. It sits inside the Broadcom Technical Specialist (BTS) program, and its objectives are published in a ten-domain study guide that maps directly to how administrators actually operate the product day to day: capturing traffic, deploying appliances, filtering data, pulling files out of packet captures, and feeding evidence into incident response workflows.

Before diving into the domains, it helps to understand the exam mechanics because they shape how you should study. The exam delivers 65-75 questions in a 90-minute window, requires a 70% passing score, and is offered in English through CertMetrics registration and Pearson VUE delivery - either at a physical test center or through OnVUE remote proctoring. It is closed book, so there is no reference material during the session. Passing requires accepting the Broadcom Software Certification Agreement, and the resulting credential stays valid for two years, after which recertification means passing whatever Broadcom Software exam version is available at that time.

If you haven't yet mapped out registration logistics or the fee structure, the ASSA80 Certification Cost breakdown and ASSA80 Exam Dates guide cover those specifics separately. This article focuses purely on the ten content domains - what each one means in practice and what you need to be able to do with the product to answer questions confidently.

Training Version vs. Exam Title: Broadcom's exam page recommends Security Analytics 8.2.5 Administration training, while the exam itself remains titled "8.0" and the study guide references 8.0.x documentation. Don't be thrown off by the version mismatch - match your practice scenarios to the ten objectives below, not to a training course number.

Domain 1: Network Traffic Visibility and Capture

The first domain establishes why Security Analytics exists: it captures network traffic as it traverses the network so that historical packet data is available for later investigation. This is the conceptual foundation the rest of the exam builds on. Candidates should understand how captured traffic gets indexed, stored, and made searchable, and why full packet capture matters compared to log-only visibility.

What to Master

Focus on the "why" before the "how" - this domain is largely conceptual.

  • The role of continuous packet capture in retrospective investigations
  • How captured data differs from flow data or log data alone
  • Where capture fits in the broader security monitoring lifecycle

Domain 2: Core Architecture - Virtual and Hardware Appliances

Domain 2 covers the core architecture of Security Analytics, including both virtual and hardware appliance form factors. Expect questions distinguishing appliance roles, component relationships, and how capture, storage, and management functions are distributed across the deployment.

  • Differences between virtual appliance deployments and physical hardware appliances
  • How appliance components communicate within a Security Analytics deployment
  • Basic capacity and storage considerations tied to appliance type

Candidates coming from a general security operations background sometimes underestimate this domain because it feels like "product trivia." Treat it as architecture literacy - you need to recognize which appliance handles which function when a scenario describes a deployment.

Domain 3: Network Architecture - TAPs vs. SPAN Ports

This domain addresses the Symantec Security Analytics network architecture requirements, specifically the differences between network TAPs and SPAN ports as traffic acquisition methods. This is one of the most heavily tested practical concepts on the exam and a frequent SEO search term for good reason - the distinction has real operational consequences.

FactorNetwork TAPSPAN Port
Traffic deliveryPassive, dedicated copy of physical trafficSwitch mirrors traffic to a designated port
Packet loss riskLower - no competition for switch resourcesHigher under switch load or oversubscription
Switch dependencyIndependent of switch configurationDepends on switch CPU/backplane capacity
Typical use caseHigh-fidelity, forensic-grade captureQuick deployment where a TAP isn't available

Key Takeaway

Expect scenario questions asking you to choose between a TAP and a SPAN port based on network segment criticality, switch capacity, or fidelity requirements - memorize the trade-offs rather than just the definitions.

Domain 4: Deployment Configuration via CLI and Web Interface

Domain 4 tests your ability to configure Security Analytics deployment, including key options within both the command-line interface and the web interface. This is where hands-on lab time pays off more than reading alone. You should be comfortable performing initial setup tasks and knowing which configuration options live in the CLI versus the web console.

Deployment Configuration

Understand configuration touchpoints on both interfaces, not just one.

  • Initial appliance setup and network configuration steps
  • Which settings require CLI access versus web interface access
  • Common deployment options administrators adjust post-install

Anyone assembling a personal lab or working through the ASSA80 Training path should spend real time toggling both interfaces rather than only reading screenshots - the exam's scenario questions often hinge on knowing where a given setting is found.

Domain 5: Filtering, Indicators, and Best Practices

This domain - performing basic and advanced filtering, creating indicators, and applying recommended filtering best practices - is arguably the operational heart of the exam. Security Analytics filtering determines whether an analyst can actually find the packets that matter inside massive capture volumes, so Broadcom weights this heavily in the objectives.

  • Building basic filters using common fields (IP, port, protocol, time range)
  • Layering advanced filters to narrow investigation scope
  • Creating indicators that flag traffic matching specific criteria automatically
  • Recommended practices for filter efficiency and avoiding overly broad queries
Why This Domain Matters Beyond the Exam: Filtering proficiency is also the skill hiring managers ask about in interviews for roles that touch Security Analytics - it's the most transferable, demonstrable competency from this domain list.

Domain 6: File Extraction and Resulting Artifacts

Domain 6 covers the file extraction process, the resulting artifacts, and the purposes they serve. Security Analytics can pull files - documents, executables, images, and other transferred objects - directly out of captured network sessions. Candidates need to understand not just how extraction works mechanically but why each artifact type matters to an investigation.

  • How the extraction process identifies and reconstructs files from packet data
  • Common artifact types produced and their forensic value
  • How extracted files support malware analysis or evidence collection

Domain 7: Cyber-Attack Anatomy, Kill Chain, and IoCs

This domain steps back from the product interface and tests conceptual security knowledge: the anatomy of a cyber-attack, the steps of the Cyber Kill Chain, and what constitutes an Indicator of Compromise (IoC). It's the domain most likely to reward candidates who already have intermediate security background, which aligns with Broadcom's stated recommendation of intermediate networking and security knowledge plus a few months of hands-on experience.

Cyber Kill Chain Essentials

Know the sequence and be able to map Security Analytics findings to each stage.

  • Reconnaissance through actions-on-objectives stage progression
  • How captured traffic evidence maps to specific kill chain stages
  • Characteristics that qualify data as a valid IoC versus noise

Domain 8: Threat Hunting and Incident Response Frameworks

Domain 8 addresses threat hunting and incident response frameworks and procedures. This builds on Domain 7's conceptual foundation and asks how an analyst actively uses Security Analytics data to hunt for threats and support a structured incident response process, rather than passively waiting for alerts.

  • Hypothesis-driven threat hunting approaches using historical capture data
  • How incident response procedures incorporate retrospective packet analysis
  • Coordinating findings between threat hunting and formal IR workflows

Retrospective investigation is a phrase worth internalizing for this domain and Domain 1 alike - the entire value proposition of the product is being able to go back in time through stored captures once a threat is suspected, rather than relying only on real-time alerts.

Domain 9: Reporting - Creation, Use, and Distribution

This domain covers how to create, use, and distribute reports in Security Analytics. Reporting questions test whether you understand the operational purpose of reports (communicating findings to stakeholders, documenting investigations) alongside the mechanics of building and sharing them.

  • Report creation workflows and available report types
  • Appropriate use cases for different report formats
  • Distribution methods for sharing reports with teams or management

Domain 10: Integrations with Symantec and Third-Party Products

The final domain describes how Security Analytics integrates with both Symantec and third-party security products. In real deployments, Security Analytics rarely operates in isolation - it feeds data to and receives context from other tools in a security stack, so this domain checks whether you understand integration points conceptually.

  • How Security Analytics shares data with other Symantec security products
  • General patterns for third-party product integration
  • Why integration matters for a unified security operations workflow

Key Takeaway

Domain 10 questions tend to be conceptual rather than deeply technical - know the purpose and pattern of integration rather than memorizing specific vendor configuration steps.

How to Weight Your Study Time Across Domains

Broadcom's study guide doesn't publish official per-domain percentage weights, so resist the urge to chase invented numbers floating around forums. Instead, weight your effort by operational complexity: domains that require hands-on interface familiarity (4, 5, 6, 9) typically need more repeated practice time than the conceptual domains (1, 2, 7, 8, 10), which reward solid reading comprehension and scenario reasoning.

Week 1

Foundations

  • Domain 1: visibility and capture concepts
  • Domain 2: appliance architecture
  • Domain 3: TAP vs. SPAN comparison drills
Week 2

Hands-On Configuration

  • Domain 4: CLI and web interface deployment tasks
  • Domain 5: build basic and advanced filters, create indicators
Week 3

Investigation Skills

  • Domain 6: practice file extraction and artifact review
  • Domain 7: memorize Cyber Kill Chain stages and IoC criteria
Week 4

Response, Reporting, and Review

  • Domain 8: threat hunting and IR procedures
  • Domain 9: reporting workflows
  • Domain 10: integration concepts
  • Full review using timed practice questions

For a more detailed week-by-week breakdown with resource recommendations, see the full ASSA80 Study Guide. If you're still deciding whether you meet the recommended background before committing to a schedule, the ASSA80 Requirements guide walks through the three-to-six months of production or lab experience Broadcom suggests.

Question Format Reminder: Official sample materials include both single-answer and multiple-response question types across these ten domains. Practice identifying when a question is asking you to select more than one correct option - misreading the format is an avoidable way to lose points on an otherwise well-studied domain.

Once you've worked through all ten domains, it's worth benchmarking your readiness against realistic scoring expectations. The ASSA80 Passing Score guide explains exactly what 70% means in terms of correct answers out of 65-75 questions, and the difficulty guide puts each domain's challenge level in context. You can also run full-length timed drills on our ASSA80 practice test platform to see which of the ten domains needs another pass before exam day.

FAQ

How many domains does the ASSA80 (250-552) exam cover?

Ten domains, as defined in Broadcom's BTS study guide, covering everything from packet capture visibility through reporting and third-party integrations.

Are all ten domains weighted equally on the exam?

Broadcom's public materials do not publish official per-domain percentages, so treat the domains as equally important to study rather than assuming any single area dominates the 65-75 question exam.

Which domain is hardest for candidates without lab access?

Domain 4 (deployment configuration via CLI and web interface) and Domain 6 (file extraction) tend to be hardest without hands-on practice, since they test interface familiarity rather than pure conceptual knowledge.

Does the training course version affect which domains are tested?

No. Broadcom recommends Security Analytics 8.2.5 Administration training, but the exam is titled 8.0 and its objectives still follow the ten domains in the 8.0.x-referenced study guide.

Where can I find more detail on registration and scoring?

See the ASSA80 Certification Cost breakdown for fee and registration mechanics, and the ASSA80 Exam Dates guide for scheduling through CertMetrics and Pearson VUE.

Ready to pass your ASSA80 exam?

Put this into practice with free ASSA80 questions across every exam domain.