
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 3
3.3 Apply the Concepts and Sequence of Steps in the Malware Analysis Process 350-201 Practice Questions (Page 6)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
30%of the exam
Questions 26–30
- 26
In reverse engineering, what is the purpose of disassembling a malware binary?
Select an answer first - 27
When setting up a sandbox for malware analysis, which practice helps reduce the chance of malware escaping the controlled environment?
Select an answer first - 28
A malware analyst has a PCAP file that contains an HTTP download of a suspicious binary. Which step is the FIRST in the process of extracting the malware sample from the PCAP?
Select an answer first - 29
A malware analyst is using a sandbox to analyze a sample that is known to delay its malicious activity until a specific date. The sandbox report shows no malicious behavior. What is the most likely reason for the lack of findings?
Select an answer first - 30
You have completed the analysis of a keylogger. Your report must include the data exfiltration method and the persistence mechanism. Which section of the report should contain this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.