Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 20

2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 5)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
7concepts
30%of the exam

Questions 21–25

  1. 21foundation · easy

    Which response action is most appropriate for a UEBA alert that indicates a user is performing data exfiltration?

    Select an answer first
  2. 22application · medium

    A security team is implementing UEBA to detect lateral movement. Which combination of SIEM data sources would provide the most complete view of user and entity behavior for this use case?

    Select an answer first
  3. 23foundation · easy

    How does UEBA typically establish a baseline of normal behavior for a user?

    Select an answer first
  4. 24application · medium

    A security operations center (SOC) analyst notices that the UEBA module in their SIEM is flagging a high number of alerts for a user who regularly works late and accesses the HR system. The user's behavior has not changed, but the alerts started after the SIEM was reconfigured to ingest data from a new cloud-based file-sharing service. What is the most likely reason for the increase in alerts?

    Select an answer first
  5. 25expert · hard

    A UEBA system uses a statistical model to detect anomalies in user login frequency. The model is trained on the last 30 days of data. A user who normally logs in 5 times per day suddenly logs in 20 times in one hour. The system generates an alert, but the SOC team finds that the user was resetting passwords for multiple accounts as part of a legitimate IT task. The team wants to prevent similar false positives in the future without losing the ability to detect genuine brute-force attacks. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.