
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 8
1.8 Describe Characteristics and Areas of Improvement Using Common Incident Response Metrics 350-201 Practice Questions (Page 3)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
15concepts
20%of the exam
Questions 11–15
- 11
A company's incident response team notices that after the SIEM generates an alert, it takes an average of 45 minutes for an analyst to acknowledge the ticket and begin initial investigation. The team wants to reduce this delay. Which metric should they track, and which improvement would most directly help?
Select an answer first - 12
An organization notices that its MTTD is consistently high. Which area of improvement is most directly indicated by this metric?
Select an answer first - 13
Which metric measures the average time from incident detection to full resolution and recovery?
Select an answer first - 14
An incident response team wants to categorize the metrics they collect to evaluate their overall performance. Which set of categories best represents the common types of incident response metrics?
Select an answer first - 15
Which metric measures the time spent on in-depth analysis and root cause investigation of an incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.