
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 6
1.6 Analyze Elements of a Risk Analysis (combination Asset, Vulnerability, and Threat) 350-201 Practice Questions (Page 4)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
6concepts
20%of the exam
Questions 16–20
- 16
A hospital's risk team is analyzing the risk to its patient records database. The database contains protected health information (PHI) and is hosted on a legacy server that is missing the latest security patches. The team has determined that a known ransomware group has been actively targeting healthcare organizations. Using a quantitative approach, the team estimates that if the database is compromised, the financial impact would be $500,000, and the likelihood of a successful exploit within the next year is 20%. What is the annualized loss expectancy (ALE) for this risk?
Select an answer first - 17
During a risk assessment for a manufacturing company, the analyst identifies that the industrial control system (ICS) that manages the assembly line has a default administrator password. The analyst also notes that a hacktivist group has recently claimed responsibility for disrupting similar manufacturers. Which of the following correctly pairs the threat with the vulnerability?
Select an answer first - 18
In a quantitative risk calculation, what does the annualized loss expectancy (ALE) represent?
Select an answer first - 19
A risk analyst is identifying assets for a risk assessment at a logistics company. The company's fleet management system tracks vehicle locations and delivery schedules. The system is critical for daily operations. Which of the following is the most appropriate way to classify this system in the risk analysis?
Select an answer first - 20
What is the role of threat identification in a risk analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.