
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 1)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 1–5
- 1
A SIEM is receiving logs from a network device that sends timestamps in a non-standard format. The correlation team wants to use time-based rules. What must be done to ensure the timestamps are usable?
Select an answer first - 2
During an incident investigation, an analyst finds an alert for a suspicious login. To determine the scope, the analyst needs to see all events from the same user and source IP across the past 72 hours. Which SIEM capability directly supports this?
Select an answer first - 3
A SIEM receives logs from a firewall (syslog), a Windows server (Event Log), and a cloud access log (JSON). The correlation team wants to write a single rule that checks for failed logins from any source. What must be configured first?
Select an answer first - 4
Which factor is most important to consider when planning SIEM data retention?
Select an answer first - 5
A company is planning a SIEM deployment and must decide how long to retain log data. Regulatory requirements mandate 12 months of retention for authentication logs, but storage costs are a concern. Which approach balances compliance and cost?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.