Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 20

2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 8)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
7concepts
30%of the exam

Questions 36–40

  1. 36expert · hard

    A SOC analyst is investigating a UEBA alert for a user who has a risk score of 95. The alert indicates the user accessed a large number of files from a file server and then attempted to access a database. The analyst checks the SIEM and finds that the user's account was used to authenticate from an IP address that is on a threat intelligence blocklist. However, the user is currently logged in to the corporate network and has an active session. What should the analyst do?

    Select an answer first
  2. 37expert · hard

    A UEBA alert flags a user who has been accessing a sensitive database at unusual times and then transferring data to an external IP address. The user's manager confirms the user is working on a project that requires data transfer to a partner. The analyst checks the SIEM and finds that the external IP address is associated with a known malicious domain. What should the analyst do?

    Select an answer first
  3. 38foundation · easy

    What does a high UEBA risk score typically indicate?

    Select an answer first
  4. 39application · medium

    A company wants to deploy UEBA to detect insider threats. The security team has access to Active Directory logs, firewall logs, and VPN logs, but no HR data or badge-access logs. Which data source is essential for building a baseline of user behavior?

    Select an answer first
  5. 40application · medium

    A company is deploying UEBA and wants to minimize false positives for users who work different shifts. The SIEM has six months of authentication logs. Which approach should the analyst take to build the baseline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.