Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 20

2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 2)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
7concepts
30%of the exam

Questions 6–10

  1. 6foundation · easy

    Which SIEM data would be most useful to correlate with a UEBA alert about a user's unusual data access?

    Select an answer first
  2. 7expert · hard

    A UEBA alert flags a user for accessing a database at an unusual time and downloading a large report. The analyst investigates and finds that the user's account is used by a batch process that runs at the same time every night. The batch process was recently moved to a new server, which changed the source IP address. The analyst also notices that the user's account has never been used for any other activity. What is the most appropriate response?

    Select an answer first
  3. 8expert · hard

    A UEBA alert shows a risk score of 70 for a user who accessed a server that is not in their normal work pattern. The analyst reviews the SIEM and finds that the user's account was used from a VPN IP that is on a blocklist. However, the user is currently in the office and has a valid active session. The analyst also notices that the user's account has multi-factor authentication (MFA) enabled and the MFA prompt was approved at the time of the VPN login. What is the most appropriate conclusion?

    Select an answer first
  4. 9application · medium

    A company is deploying UEBA for the first time. The SIEM has been collecting authentication and file access logs for only two weeks. The UEBA administrator is concerned that the baseline will not be accurate. What should the administrator do?

    Select an answer first
  5. 10foundation · easy

    When investigating a UEBA alert, what is the first step an analyst should take using SIEM data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.