Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 4Objective 1

4.1 Compare Concepts, Platforms, and Mechanisms of SOAR 350-201 Practice Questions (Page 4)

Part of the Automation domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts
20%of the exam

Questions 16–20

  1. 16expert · hard

    A SOC team is using a SOAR platform to handle phishing incidents. The current playbook automatically extracts URLs and checks them against a threat intelligence feed. If the URL is malicious, the playbook automatically blocks it in the proxy and sends a notification to the user. However, the team has received complaints that some legitimate URLs are being blocked. What is the most likely cause and what is the best solution?

    Select an answer first
  2. 17expert · hard

    A SOC team is implementing a SOAR platform and wants to automate the response to a specific type of malware alert. The playbook should automatically quarantine the affected endpoint, but only if the endpoint is not a critical server. If it is a critical server, the playbook should only create a high-priority ticket for manual review. The team also wants to ensure that the quarantine action is reversible. Which playbook design best meets these requirements?

    Select an answer first
  3. 18application · medium

    A small security team is overwhelmed by the volume of alerts and often misses critical incidents because they spend too much time on repetitive tasks like gathering context and opening tickets. They want a solution that helps them prioritize alerts and automates the initial investigation steps. Which solution best addresses this need?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of a Security Orchestration, Automation, and Response (SOAR) platform?

    Select an answer first
  5. 20application · medium

    A security operations team receives hundreds of low-severity alerts daily from their SIEM. They want to automatically enrich each alert with threat intelligence, check if the involved IPs are on a blocklist, and if so, automatically create a ticket in their ticketing system for a human analyst to review. The team wants to minimize manual effort while keeping a human in the loop for any action that could disrupt services. Which approach best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.