Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 1

3.1 Analyze Components in a Threat Model 350-201 Practice Questions (Page 8)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
9concepts
30%of the exam

Questions 36–40

  1. 36application · medium

    A security analyst has completed a threat model for a new application and needs to document the findings for the development team. The team needs to understand which threats are most critical and what actions to take. Which documentation format is most effective for this audience?

    Select an answer first
  2. 37application · medium

    A hospital's patient portal allows patients to log in, view lab results, and send messages to their care team. The portal is hosted in a public cloud, and the database containing PHI is in a separate VPC. The application server queries the database over a private network connection. During a threat modeling exercise, the team maps the data flow and identifies that the application server can reach the database without any authentication. Which component of the threat model should be flagged as the highest priority to address?

    Select an answer first
  3. 38application · medium

    A threat modeling team is assessing a new online voting system. They are considering the threat actor 'a politically motivated group with moderate technical skills'. Which attack vector is most likely to be used by this actor?

    Select an answer first
  4. 39application · medium

    During a threat model review, the team discovers that a legacy application stores database credentials in plaintext in a configuration file. The application is critical to business operations and cannot be immediately rewritten. Which mitigation should be implemented first?

    Select an answer first
  5. 40foundation · easy

    Which statement best describes the role of threat modeling in the software development lifecycle?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.