Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 22

2.22 Describe Tools and Their Limitations for Network Analysis Such as Packet Capture Tools, Traffic Analysis Tools, Network Log Analysis Tools 350-201 Practice Questions (Page 1)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts
30%of the exam

Questions 1–5

  1. 1foundation · medium

    What is a key function of a network log analysis tool in a security incident investigation?

    Select an answer first
  2. 2application · medium

    A security operations center (SOC) receives logs from firewalls, IDS/IPS, and authentication servers. The SOC wants to correlate a specific user's failed login attempts with firewall blocks that occurred at the same time. Which tool is most appropriate for this task?

    Select an answer first
  3. 3expert · hard

    A SOC is correlating logs from multiple sources to identify a multi-stage attack. The analysts notice that events from the firewall and the IDS are not aligning correctly, even though both devices are configured to send logs to the same SIEM. The SIEM shows that the firewall logs are delayed by about 5 minutes compared to the IDS logs. What is the most likely cause and the best corrective action?

    Select an answer first
  4. 4expert · hard

    A network engineer is asked to capture traffic for a legal investigation. The traffic is encrypted TLS, and the engineer has access to the server's private key. The capture must be complete and legally admissible. The engineer has a capture appliance with limited storage. What is the most important consideration?

    Select an answer first
  5. 5application · medium

    A network engineer must capture all traffic on a high-throughput 10 Gbps link for a 24-hour period to investigate a possible slow data exfiltration. The capture server has a 2 TB RAID array. The engineer estimates the average traffic rate at 3 Gbps. What is the primary constraint the engineer must address?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.