
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 1
3.1 Analyze Components in a Threat Model 350-201 Practice Questions (Page 9)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
9concepts
30%of the exam
Questions 41–44
- 41
During a threat model review of a web application, the team finds that the application uses an outdated library with a known remote code execution vulnerability. The library is used in a component that processes user-uploaded files. What should be the immediate recommendation?
Select an answer first - 42
A security team is using DREAD to score threats for a new online banking feature. They have identified a threat that allows an attacker to transfer funds from any account. The team rates the damage as 10, reproducibility as 10, exploitability as 5, affected users as 10, and discoverability as 5. What is the DREAD risk score?
Select an answer first - 43
What is the purpose of developing mitigation strategies in threat modeling?
Select an answer first - 44
In the context of threat modeling, what is the primary purpose of asset identification and classification?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.