
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 7
1.7 Apply the Incident Response Workflow 350-201 Practice Questions (Page 1)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
20%of the exam
Questions 1–5
- 1
After a ransomware incident is contained and eradicated, the incident response team conducts a post-incident review. The review identifies that the initial detection was delayed because the security operations center (SOC) did not have a documented escalation path for suspicious alerts. Which action best addresses this finding?
Select an answer first - 2
A forensic investigator is collecting evidence from a compromised server. The server is part of a cluster and must remain available for business operations. The investigator needs to preserve evidence without taking the server offline. Which approach best meets both requirements?
Select an answer first - 3
A security operations center (SOC) receives an alert about a possible malware infection on a finance department workstation. The alert is based on a single endpoint detection and response (EDR) signal. The SOC analyst must decide whether to escalate the incident. The company has a low tolerance for false positives. What should the analyst do first?
Select an answer first - 4
An incident response team is handling a malware infection that has spread to multiple systems. The team has contained the spread and is now deciding whether to begin eradication or first conduct a deeper analysis of the malware's capabilities. Which consideration is most important in this decision?
Select an answer first - 5
During an active incident, the incident response team discovers that the attack originated from a partner organization's network. The team needs to coordinate with the partner to stop the attack. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.