
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 7
1.7 Apply the Incident Response Workflow 350-201 Practice Questions (Page 3)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
20%of the exam
Questions 11–15
- 11
An organization is developing its incident response plan. The plan must address the possibility of a ransomware attack that could affect both on-premises and cloud systems. Which preparatory measure is most important to ensure an effective response?
Select an answer first - 12
An organization discovers that an attacker has compromised a database server and is actively exfiltrating sensitive customer data. The incident response team must contain the incident while preserving evidence for a potential lawsuit. Which containment strategy best balances these competing needs?
Select an answer first - 13
A network analyst sees a sudden spike in outbound traffic from a file server to an external IP address on port 443. The traffic pattern is periodic and occurs every 5 minutes. The analyst suspects a data exfiltration. What should the analyst do next to confirm and scope the incident?
Select an answer first - 14
What is the primary purpose of maintaining a chain of custody for evidence collected during an incident?
Select an answer first - 15
Which of the following is an example of external coordination during an incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.