
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 10)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 46–50
- 46
Which challenge does log normalization address in a SIEM deployment?
Select an answer first - 47
Which of the following is a common data source ingested by a SIEM tool?
Select an answer first - 48
A company is deploying a SIEM and must ingest logs from multiple regional offices with limited WAN bandwidth. The SIEM must still provide centralized correlation and alerting. Which deployment approach best addresses the bandwidth constraint?
Select an answer first - 49
Which SIEM feature is most useful for an analyst investigating a potential breach?
Select an answer first - 50
A SIEM administrator is configuring a new data source that produces logs in a proprietary format. The security team wants these logs to be searchable alongside existing sources and included in correlation rules. What must the administrator do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.