
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 8
1.8 Describe Characteristics and Areas of Improvement Using Common Incident Response Metrics 350-201 Practice Questions (Page 1)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
15concepts
20%of the exam
Questions 1–5
- 1
A security analyst receives an alert from the SIEM at 14:00 and acknowledges it at 14:30. The analyst then begins the initial investigation at 14:45. Which metric is 30 minutes, and what improvement would most directly reduce it?
Select an answer first - 2
Which metric measures the time to restore normal operations after eradication?
Select an answer first - 3
A SOC analyst detects a potential intrusion at 09:00 and completes the initial assessment and prioritization at 09:40. The analyst then begins a deep dive into the logs at 09:45. Which metric is 40 minutes, and what improvement would most directly reduce it?
Select an answer first - 4
A company wants to quantify the financial impact of a recent security incident. They have calculated the cost of forensic investigation, legal fees, and notification costs. They also estimated the lost productivity of employees during the outage. Which type of cost does the lost productivity represent?
Select an answer first - 5
What does the 'cost per incident' metric typically represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.