
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 16
2.16 Describe the Concepts of Security Data Management 350-201 Practice Questions (Page 6)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 26–30
- 26
A SOC analyst is triaging an alert that shows a host making outbound connections to a rarely used external IP. The IP is not in any threat intelligence feed. The analyst wants to determine if this is malicious without overwhelming the SIEM with false positives. The analyst has access to DNS logs, proxy logs, and endpoint process data. What is the best next step?
Select an answer first - 27
A SIEM analyst notices that firewall logs record source IP as 'src_ip', while VPN logs use 'SourceAddress'. The analyst wants to correlate login events across both sources. What is the most effective first step?
Select an answer first - 28
A SOC analyst is reviewing an alert that shows outbound traffic from an internal host to an external IP address. The alert was generated by the firewall, but the analyst needs to know if this IP address is known for malicious activity and whether the host has any other suspicious behavior. What should the analyst do to improve the investigation?
Select an answer first - 29
A SIEM receives logs from a firewall, an endpoint, and a web server. Each source uses a different timestamp format and field naming convention. What process allows the SIEM to analyze these logs together?
Select an answer first - 30
A SOC is overwhelmed by false positives from a correlation rule that flags any internal host connecting to a known malicious IP. The analyst wants to reduce false positives while maintaining detection of real threats. Which enrichment should be added to the rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.