
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 1
3.1 Analyze Components in a Threat Model 350-201 Practice Questions (Page 2)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
9concepts
30%of the exam
Questions 6–10
- 6
Which of the following is an example of a data asset in a threat model?
Select an answer first - 7
A multinational corporation is threat modeling its global HR system, which stores employee data for all regions. The system is hosted in a single data center in the United States. The company is expanding into the European Union and must comply with GDPR. The threat model must account for data residency requirements. Which asset classification and risk consideration is most appropriate?
Select an answer first - 8
A company's threat model for a web application identifies a cross-site scripting (XSS) vulnerability in a search feature. The application is public-facing and used by customers. The team is considering two mitigations: (1) implementing output encoding, and (2) adding a web application firewall (WAF) rule to block XSS payloads. The company has a strict budget and wants the most reliable mitigation. Which should they choose?
Select an answer first - 9
A company has a legacy system that processes credit card transactions. The threat model identifies a critical vulnerability in the system that could allow an attacker to steal card data. The company has limited budget and must choose between two mitigations: (1) implementing network segmentation to isolate the system, or (2) upgrading the system to a modern, patched platform. The upgrade is expensive and may cause downtime. The company's compliance requirements mandate that card data must be protected. Which approach should the company take?
Select an answer first - 10
A financial services company is conducting a threat model for its new mobile banking application. The team must identify which assets are most critical to protect. The application stores user credentials, transaction history, and the app's source code in a repository. Which asset should be classified as having the highest criticality for confidentiality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.