
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 12
2.12 Apply AI-driven Threat Intelligence Using Tools 350-201 Practice Questions (Page 7)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
30%of the exam
Questions 31–35
- 31
A mid-sized company wants to implement an AI-driven threat intelligence platform to improve its security posture. The company has a small security team and limited budget. They need a solution that can aggregate threat data from multiple sources, provide automated correlation, and integrate with their existing SIEM. Which type of solution should they choose?
Select an answer first - 32
A large enterprise is considering two AI-driven threat intelligence platforms. Platform X uses supervised learning and requires labeled data from the organization to train its models. Platform Y uses unsupervised learning and does not require labeled data. The organization has a mature security team but limited labeled data. They want to quickly deploy a platform that can detect unknown threats. Which platform should they choose?
Select an answer first - 33
A security analyst at a mid-sized company is reviewing alerts from the AI-driven threat intelligence platform. The platform flags a domain as malicious because it was observed in a phishing campaign last month. However, the domain is currently used by the company's marketing team for a legitimate email campaign. The analyst must decide whether to block the domain. What should the analyst do first?
Select an answer first - 34
A security team is evaluating two AI-driven threat intelligence platforms. Platform A has a high detection rate but generates many false positives, overwhelming the SOC. Platform B has a lower detection rate but produces very few false positives, allowing the team to focus on high-confidence alerts. The team has limited staffing and cannot handle a high volume of alerts. Which platform should they choose, and why?
Select an answer first - 35
A company is deploying an AI-driven threat intelligence platform to aggregate data from multiple sources, including open-source feeds, commercial feeds, and internal telemetry. The platform uses machine learning to correlate indicators and provide a unified view. The security team wants to ensure the platform's outputs are actionable for their SOC. What is the most important capability to verify?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.