Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 8

1.8 Describe Characteristics and Areas of Improvement Using Common Incident Response Metrics 350-201 Practice Questions (Page 5)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
15concepts
20%of the exam

Questions 21–25

  1. 21foundation · easy

    Which effectiveness metric measures the percentage of incidents that are successfully contained without further spread?

    Select an answer first
  2. 22expert · hard

    A company experienced two incidents in the past year. Incident A had a direct cost of $50,000 and indirect cost of $100,000. Incident B had a direct cost of $30,000 and indirect cost of $80,000. The company wants to reduce the financial impact of future incidents. Which metric should they use to compare the incidents, and what insight does it provide?

    Select an answer first
  3. 23application · medium

    A SOC notices that the SIEM generates a high number of alerts, but many are false positives. The team wants to assess the quality of their detection and response processes. Which metric should they track, and what improvement would most directly help?

    Select an answer first
  4. 24application · medium

    During a ransomware incident, the response team isolates affected hosts and blocks the command-and-control IP addresses. The team records that it took 6 hours from initial detection to complete isolation of all affected systems. Which metric does this 6-hour figure represent, and what improvement would most directly reduce it?

    Select an answer first
  5. 25application · medium

    A security team is reviewing a recent malware incident. The team detected the malware at 10:00, contained it at 12:00, eradicated it at 14:00, and restored all systems to normal operation by 18:00. Which metric would be 8 hours, and what does it indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.