
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 3
2.3 Describe the Process of Evaluating the Security Posture of an Asset 350-201 Practice Questions (Page 3)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
30%of the exam
Questions 11–15
- 11
A security team is performing a risk analysis for a new IoT device deployment. The devices are low-cost and have limited processing power, making it difficult to run endpoint protection. The devices collect non-sensitive telemetry data and are isolated on a separate network. The team must score the risk for these devices. What is the most appropriate risk score?
Select an answer first - 12
A company is evaluating the security posture of its public-facing web application. The application is protected by a web application firewall (WAF) and requires multi-factor authentication (MFA) for admin access. During the assessment, the team discovers that the application uses an outdated version of a JavaScript library with a known remote code execution vulnerability. What should the team do next in the posture evaluation process?
Select an answer first - 13
What is the primary purpose of evaluating the security posture of an asset?
Select an answer first - 14
A security team has completed a posture assessment and identified that a critical application has a high-risk vulnerability. The remediation requires a significant investment and a maintenance window. The team must present the findings to the executive board. What is the most effective way to communicate the risk and remediation plan?
Select an answer first - 15
A large organization is evaluating the security posture of its fleet of 5,000 endpoints. The endpoints include laptops, desktops, and mobile devices. The security team has limited resources and must complete the evaluation within two weeks. They have a vulnerability scanner that can scan all endpoints, but the scan results are noisy and require manual triage. The team also has a list of critical assets from a recent business impact analysis. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.