
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 1
3.1 Analyze Components in a Threat Model 350-201 Practice Questions (Page 5)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
9concepts
30%of the exam
Questions 21–25
- 21
A manufacturing company's ICS/SCADA environment has been targeted by a series of phishing emails that contain malware designed to disrupt production. The threat model needs to profile the likely threat actor. Which actor profile best matches this scenario?
Select an answer first - 22
In threat actor profiling, what does 'capability' refer to?
Select an answer first - 23
A security analyst is evaluating a new microservices-based application. The team wants to identify all possible ways an attacker could compromise the system, including multi-step attack paths that chain multiple vulnerabilities. Which threat modeling approach is best suited for this analysis?
Select an answer first - 24
What is the primary purpose of threat modeling in the context of cybersecurity?
Select an answer first - 25
During a threat modeling session for a web application, the team identifies that user-supplied input is passed directly to a SQL query without sanitization. The application is behind a WAF. Which vulnerability and exploit analysis finding should be documented as the most critical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.