
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 16
2.16 Describe the Concepts of Security Data Management 350-201 Practice Questions (Page 10)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 46–50
- 46
A security team is designing a data lifecycle for security logs. They must comply with a privacy regulation that requires personal data to be deleted when no longer needed. Which lifecycle stage should be explicitly defined to meet this requirement?
Select an answer first - 47
A security team needs to collect security data from a cloud-based SaaS application that provides an HTTP-based interface for exporting logs. Which data collection method is most appropriate?
Select an answer first - 48
A SOC is investigating a potential compromise. The SIEM receives logs from firewalls, endpoint detection and response (EDR), and Active Directory. The logs are normalized, but the SOC has not yet integrated threat intelligence feeds. The analyst wants to identify all hosts that communicated with a known command-and-control (C2) IP address in the last 24 hours. The C2 IP is not yet in the SIEM's threat intelligence. What is the most efficient approach?
Select an answer first - 49
What is the main goal of data correlation in security monitoring?
Select an answer first - 50
Which factor is most important when determining how long to retain security logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.