Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 22

2.22 Describe Tools and Their Limitations for Network Analysis Such as Packet Capture Tools, Traffic Analysis Tools, Network Log Analysis Tools 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    A security analyst is using Wireshark to analyze a packet capture from a compromised host. The analyst needs to see the contents of an HTTPS session. The analyst has the server's private key. What should the analyst do to view the decrypted traffic?

    Select an answer first
  2. 17foundation · medium

    A security operations center (SOC) needs to collect logs from firewalls, servers, and applications into a central location for analysis. Which type of tool is designed for this purpose?

    Select an answer first
  3. 18application · medium

    A security analyst is reviewing logs from multiple network devices to trace an attack path. The analyst notices that some devices do not log certain events, such as failed login attempts on a legacy switch. What limitation of network log analysis tools is the analyst encountering?

    Select an answer first
  4. 19application · medium

    A network engineer needs to capture traffic on a high-availability link between two data centers to troubleshoot an application performance issue. The engineer has a server with two 10 Gbps NICs and a RAID array. The link is a 10 Gbps link. Which capture strategy is most appropriate?

    Select an answer first
  5. 20application · medium

    A security analyst is using a traffic analysis tool to identify a possible DNS tunneling attack. The tool provides flow data but not the content of DNS queries. What should the analyst do to gain more visibility into the DNS payloads?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.