Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 22

2.22 Describe Tools and Their Limitations for Network Analysis Such as Packet Capture Tools, Traffic Analysis Tools, Network Log Analysis Tools 350-201 Practice Questions (Page 2)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts
30%of the exam

Questions 6–10

  1. 6expert · hard

    A security analyst is using NetFlow to investigate a potential data exfiltration. The analyst sees a flow to an external IP with a high byte count, but the flow duration is very short. The analyst suspects the byte count may be inaccurate. Which factor is most likely to cause the byte count to be inaccurate?

    Select an answer first
  2. 7expert · hard

    A security team must investigate a suspected data exfiltration that occurred over a 10 Gbps internet link. The team has a capture appliance with 8 TB of storage and a 10 Gbps NIC. The exfiltration is believed to have used HTTPS to a single external IP. The team needs to preserve evidence for potential legal action. Which approach best balances completeness and feasibility?

    Select an answer first
  3. 8application · medium

    A security team is using NetFlow to detect large data transfers to an external IP. The team notices that some large transfers are not appearing in the flow data. Which limitation of traffic analysis tools is most likely responsible?

    Select an answer first
  4. 9application · medium

    A security analyst is correlating VPN login events with firewall logs to investigate an intrusion. The analyst notices that events that should have occurred at the same time appear to be out of order. Which limitation of network log analysis tools is most likely causing this issue?

    Select an answer first
  5. 10application · medium

    A network analyst is using NetFlow to investigate a possible data exfiltration. The analyst notices that the flow records show only a fraction of the traffic that the firewall logs indicate. What is the most likely cause of this discrepancy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.