Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 6

1.6 Analyze Elements of a Risk Analysis (combination Asset, Vulnerability, and Threat) 350-201 Practice Questions (Page 5)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
6concepts
20%of the exam

Questions 21–25

  1. 21foundation · easy

    What is the primary purpose of a vulnerability assessment in the risk analysis process?

    Select an answer first
  2. 22expert · hard

    A financial services firm is conducting a risk analysis for its new online banking platform. The platform handles customer transactions and stores sensitive account data. The risk team has identified the following: - Asset: Customer transaction database (criticality: high) - Vulnerability: The web application firewall (WAF) is misconfigured, allowing some SQL injection attempts to reach the application server. - Threat: An organized cybercrime group known for targeting financial institutions. The team must choose between a qualitative and a quantitative approach. The organization has limited historical incident data for this platform, but executives need a clear, comparable ranking of risks to justify security investments. Which approach is most appropriate in this situation?

    Select an answer first
  3. 23expert · hard

    A multinational corporation is conducting a risk analysis for its intellectual property (IP) stored in a cloud environment. The company has a mature security program and extensive historical data on security incidents. However, the threat landscape is changing, and the company's executives want a clear, objective way to compare risks across different business units. Which approach should the risk team use?

    Select an answer first
  4. 24foundation · easy

    Which of the following best describes a qualitative risk analysis method?

    Select an answer first
  5. 25expert · hard

    A cybersecurity team is analyzing risks for a hospital's medical device network. The team has identified the following: - Asset: Infusion pumps (critical for patient care) - Vulnerability: The pumps run on an outdated operating system with known unpatched vulnerabilities - Threat: Malware that can spread through the network The team must decide whether to use a qualitative or quantitative approach. The hospital has no historical incident data for these devices, but the potential impact of a compromise is very high. The team needs to communicate the risk to non-technical executives. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.