Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 22

2.22 Describe Tools and Their Limitations for Network Analysis Such as Packet Capture Tools, Traffic Analysis Tools, Network Log Analysis Tools 350-201 Practice Questions (Page 8)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts
30%of the exam

Questions 36–40

  1. 36expert · hard

    A SOC is investigating a potential advanced persistent threat. The team has a SIEM that ingests logs from firewalls, proxies, and endpoints. The SIEM is receiving logs from a firewall that is not NTP-synchronized, and the proxy logs are missing entries for certain users due to a misconfiguration. The team needs to correlate a specific user's activity across all sources. What is the best course of action?

    Select an answer first
  2. 37foundation · medium

    An analyst is using a traffic analysis tool to investigate a security incident and needs to see the actual payload of a suspicious HTTP request. Which limitation of traffic analysis tools prevents this?

    Select an answer first
  3. 38foundation · medium

    A SOC analyst is correlating logs from multiple devices to trace an attack. The analyst notices that events from different devices appear out of order. Which limitation of network log analysis tools is most likely causing this?

    Select an answer first
  4. 39application · medium

    A SOC analyst is investigating a security incident and needs to determine whether a specific user logged into a server at a particular time. The analyst checks the log analysis platform and finds that the authentication server's logs for that time period are missing. Which limitation of network log analysis tools is most likely the cause?

    Select an answer first
  5. 40application · medium

    A security analyst needs to capture traffic between two internal servers during a suspected data exfiltration event. The servers communicate over HTTPS on port 443, and the analyst has administrative access to both servers. The analyst wants to see the actual payload content exchanged. Which approach should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.