
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 20
2.20 Analyze Anomalous User and Entity Behavior (UEBA) Using SIEM Data 350-201 Practice Questions (Page 9)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
7concepts
30%of the exam
Questions 41–42
- 41
A SOC analyst reviews a UEBA alert for a finance user who has a risk score of 85 (scale 0-100). The alert indicates the user accessed 15 GB of data from a file share at 2:00 AM, which is unusual for this user. The analyst checks the SIEM and finds that the user's account was used to authenticate from an IP address known to be associated with a previous malware infection. What should the analyst do first?
Select an answer first - 42
A SIEM administrator wants to configure UEBA to detect a user who suddenly starts accessing systems at 3:00 AM when they normally work 9 AM to 5 PM. The administrator has six months of authentication logs and wants to minimize false positives. Which approach should the administrator choose?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.