Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 16

2.16 Describe the Concepts of Security Data Management 350-201 Practice Questions (Page 7)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts
30%of the exam

Questions 31–35

  1. 31application · medium

    An organization ingests firewall logs, DNS logs, and endpoint detection alerts into its SIEM. The SIEM correlates events by source IP, destination IP, and timestamp, but the logs use different field names and timestamp formats. What should the analyst do first to enable effective correlation?

    Select an answer first
  2. 32foundation · easy

    A SIEM correlates a failed login event on a server with a subsequent successful login from the same source IP and then an outbound data transfer. What does this correlation help the analyst identify?

    Select an answer first
  3. 33application · medium

    A security analyst needs to collect authentication logs from 200 Windows servers and 50 Linux servers for centralized monitoring. The servers are in a mix of on-premises and cloud environments, and the analyst needs near-real-time log delivery with minimal configuration on each host. Which data collection method should the analyst choose?

    Select an answer first
  4. 34application · medium

    A SOC manager wants to provide executives with a high-level view of security incidents over the past month. The executives need to understand trends without technical details. Which visualization is most appropriate?

    Select an answer first
  5. 35application · medium

    A financial institution is required by regulation to retain transaction logs for seven years. The logs are stored in a SIEM that has limited storage capacity. The compliance team wants to ensure logs are available for audits, while the security team wants to keep the SIEM performance optimal. What should the organization do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.