
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 3
3.3 Apply the Concepts and Sequence of Steps in the Malware Analysis Process 350-201 Practice Questions (Page 2)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
30%of the exam
Questions 6–10
- 6
You have a suspicious DLL file that you need to analyze without executing it. You want to determine if it exports any functions that could be used for persistence. Which static analysis technique is most appropriate?
Select an answer first - 7
During an incident, you have a packet capture that contains a malware download over HTTP. You need to extract the executable and verify its hash. Which steps should you take?
Select an answer first - 8
What is the primary purpose of dynamic malware analysis in a sandbox?
Select an answer first - 9
An analyst is examining a PCAP file and wants to extract all files transferred over HTTP. Which feature in Wireshark is designed for this purpose?
Select an answer first - 10
An analyst has executed a malware sample in a sandbox and observed that it creates a scheduled task and modifies a registry key, but the network traffic is encrypted and the analyst cannot determine the purpose of the communication. The sample is packed, and static analysis has not yet been performed. What should the analyst do next to gain a comprehensive understanding of the malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.