Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 20

2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 9)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
7concepts
30%of the exam

Questions 41–42

  1. 41application · medium

    A SOC analyst reviews a UEBA alert for a finance user who has a risk score of 85 (scale 0-100). The alert indicates the user accessed 15 GB of data from a file share at 2:00 AM, which is unusual for this user. The analyst checks the SIEM and finds that the user's account was used to authenticate from an IP address known to be associated with a previous malware infection. What should the analyst do first?

    Select an answer first
  2. 42application · medium

    A SIEM administrator wants to configure UEBA to detect a user who suddenly starts accessing systems at 3:00 AM when they normally work 9 AM to 5 PM. The administrator has six months of authentication logs and wants to minimize false positives. Which approach should the administrator choose?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 350-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.