
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 3
3.3 Apply the Concepts and Sequence of Steps in the Malware Analysis Process 350-201 Practice Questions (Page 3)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
30%of the exam
Questions 11–15
- 11
An analyst is investigating a network intrusion and has a packet capture that contains a malicious payload delivered over HTTP. The analyst needs to extract the payload and determine its file type before performing static analysis. Which sequence of steps should the analyst follow?
Select an answer first - 12
You are analyzing a piece of malware that uses a rootkit to hide its processes. In your sandbox, you cannot see the malicious process in the process list, but you can see its network connections. What is the most effective way to confirm the hidden process and analyze its behavior?
Select an answer first - 13
During static analysis of a Windows malware sample, an analyst discovers that the binary contains an embedded DLL and uses a custom packing algorithm. The analyst needs to understand the malware's core functionality without executing it. Which technique should the analyst apply first?
Select an answer first - 14
You are analyzing a trojan that only activates when it detects a specific domain name resolution failure. In your sandbox, the domain resolves successfully, so the trojan remains dormant. What should you do to trigger the malicious behavior?
Select an answer first - 15
What is a common limitation of using a sandbox for dynamic malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.