Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 20

2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
7concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    A UEBA alert indicates that a user's account is performing administrative actions outside of business hours, which is unusual for that user. The analyst verifies that the user is on vacation and has no scheduled tasks. What is the most appropriate immediate response?

    Select an answer first
  2. 17expert · hard

    A company has a SIEM with UEBA. The UEBA baseline for a user is built from the last 90 days of authentication logs. The user normally logs in from the office between 8 AM and 6 PM. The company recently implemented a work-from-home policy, and the user now logs in from home at various times. The UEBA system is generating a high number of alerts for this user. The SOC team wants to reduce false positives without losing detection capability. What should they do?

    Select an answer first
  3. 18application · medium

    A UEBA alert fires for a finance user who has never accessed the HR file share before. The alert shows the user copied 500 files from the HR share to a USB drive. The user's manager confirms the user recently transferred to the HR department. Which action should the analyst take first?

    Select an answer first
  4. 19foundation · easy

    Which machine learning approach is often used by UEBA to detect anomalies without labeled data?

    Select an answer first
  5. 20expert · hard

    A SOC analyst is reviewing three UEBA alerts with the following risk scores and context: Alert 1: score 95, user downloaded 10 GB from a file share (user is a data scientist). Alert 2: score 80, user logged in from a new country and then accessed a finance system (user is in sales). Alert 3: score 75, user accessed a server at 2 AM (user is an IT admin who has on-call duties). The SOC has time to investigate only one alert. Which alert should be investigated first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.