
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 20
2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 7)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
7concepts
30%of the exam
Questions 31–35
- 31
A UEBA alert flags a user for sending a large number of emails with attachments to external addresses. The analyst investigates and finds that the user is a marketing manager who regularly sends campaign emails. However, the volume is three times higher than the user's normal pattern. The user's manager confirms the user is running a new campaign. What is the most appropriate response?
Select an answer first - 32
A UEBA alert flags a user who has downloaded a large amount of data from a database and then attempted to access another database that is not part of their normal job function. The user's manager confirms the user is on a temporary project that requires cross-database access. What is the most appropriate response?
Select an answer first - 33
A SIEM administrator is planning to deploy UEBA and wants to ensure the analytics can detect anomalies in user behavior such as unusual login times and data access patterns. Which combination of data sources should the administrator prioritize for ingestion?
Select an answer first - 34
Which of the following is a common statistical technique used by UEBA to detect anomalies?
Select an answer first - 35
After confirming a UEBA alert indicates a compromised account, what is an appropriate immediate response action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.