Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 7

1.7 Apply the Incident Response Workflow 350-201 Practice Questions (Page 1)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
8concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    After a ransomware incident is contained and eradicated, the incident response team conducts a post-incident review. The review identifies that the initial detection was delayed because the security operations center (SOC) did not have a documented escalation path for suspicious alerts. Which action best addresses this finding?

    Select an answer first
  2. 2expert · hard

    A forensic investigator is collecting evidence from a compromised server. The server is part of a cluster and must remain available for business operations. The investigator needs to preserve evidence without taking the server offline. Which approach best meets both requirements?

    Select an answer first
  3. 3expert · hard

    A security operations center (SOC) receives an alert about a possible malware infection on a finance department workstation. The alert is based on a single endpoint detection and response (EDR) signal. The SOC analyst must decide whether to escalate the incident. The company has a low tolerance for false positives. What should the analyst do first?

    Select an answer first
  4. 4expert · hard

    An incident response team is handling a malware infection that has spread to multiple systems. The team has contained the spread and is now deciding whether to begin eradication or first conduct a deeper analysis of the malware's capabilities. Which consideration is most important in this decision?

    Select an answer first
  5. 5application · medium

    During an active incident, the incident response team discovers that the attack originated from a partner organization's network. The team needs to coordinate with the partner to stop the attack. What should the team do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.