
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 7
1.7 Apply the Incident Response Workflow 350-201 Practice Questions (Page 9)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
20%of the exam
Questions 41–45
- 41
A security analyst detects a worm spreading across the corporate network. The incident response team needs to stop the spread immediately while preserving forensic evidence for later analysis. Which action should the team take first?
Select an answer first - 42
During a major security incident, the incident response team needs to coordinate with external parties, including law enforcement and a third-party forensic firm. Which action best supports effective coordination?
Select an answer first - 43
An organization has just experienced a security incident. The incident response team has completed the containment and eradication phases. According to the incident response workflow, what should the team do next?
Select an answer first - 44
A security analyst detects a suspicious process running on a critical server. The process is making outbound connections to a known command-and-control (C2) domain. The analyst must confirm the incident without disrupting the investigation. Which action is most appropriate?
Select an answer first - 45
Which activity is part of the detection and analysis phase of incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.