Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 6

1.6 Analyze Elements of a Risk Analysis (combination Asset, Vulnerability, and Threat) 350-201 Practice Questions (Page 6)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
6concepts
20%of the exam

Questions 26–30

  1. 26application · medium

    A security analyst has completed a risk assessment for a mid-sized company and compiled the following data: - Risk A: Customer database exposed to the internet; likelihood 0.8, impact $200,000 - Risk B: Internal file server with weak passwords; likelihood 0.5, impact $50,000 - Risk C: Legacy application with known unpatched vulnerability; likelihood 0.3, impact $400,000 - Risk D: Office Wi-Fi using WPA2 with a shared password; likelihood 0.2, impact $10,000 Based on quantitative risk scores (likelihood × impact), which risk should be prioritized for mitigation first?

    Select an answer first
  2. 27expert · hard

    A government agency is performing a risk analysis for a new citizen portal. The portal will collect personal data and must comply with strict data protection regulations. The agency has historical data from similar systems, but the threat landscape is evolving rapidly. The risk team must decide between a qualitative and a quantitative approach. The agency's leadership wants a defensible, data-driven ranking of risks, but also needs to incorporate expert judgment about emerging threats. Which approach best meets these requirements?

    Select an answer first
  3. 28application · medium

    A utility company is performing a risk analysis for its smart grid management system. The system has a known vulnerability in its firmware update process. The company has received a warning from a national cybersecurity agency about a state-sponsored group that has been targeting utility companies. Which of the following is the threat in this scenario?

    Select an answer first
  4. 29application · medium

    A security consultant is helping a hospital identify assets for a risk analysis. The hospital's network includes an electronic health record (EHR) system, a building access control system, and a public website. Which asset should be classified as having the highest criticality for patient safety?

    Select an answer first
  5. 30application · medium

    During a risk assessment, an analyst discovers that a web server is running an outdated version of the Apache HTTP Server with a known vulnerability that allows directory traversal. The server hosts the company's public marketing site, which does not contain sensitive data. How should this vulnerability be characterized in the risk analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.