
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 11)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 51–54
- 51
During an incident investigation, an analyst identifies a suspicious login from an IP address. The analyst wants to see all other events involving that IP across the entire environment, including authentication, network flows, and endpoint logs. Which SIEM capability directly supports this investigation step?
Select an answer first - 52
An analyst needs to detect a multi-stage attack where an attacker first performs a port scan, then exploits a vulnerability, and later establishes a command-and-control channel. The SIEM receives NetFlow, vulnerability scan results, and threat intelligence feeds. Which approach is most effective?
Select an answer first - 53
What is an example of threat intelligence data that a SIEM might use to enrich security events?
Select an answer first - 54
An organization uses a free threat intelligence feed that updates daily, but the SOC is seeing an increasing number of false positives because the feed contains many expired indicators. The team wants to improve detection accuracy without increasing budget. What is the best approach?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.