Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 17

2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 3)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts
30%of the exam

Questions 11–15

  1. 11expert · hard

    A SOC is expanding its SIEM to ingest logs from 50 new branch offices. The current SIEM is struggling with ingestion lag, and the team must decide between increasing storage capacity or upgrading the correlation engine. The compliance team also requires 18 months of log retention. Which approach best addresses the immediate performance issue while meeting retention?

    Select an answer first
  2. 12expert · hard

    During an incident, an analyst identifies a malicious file hash from a sandbox report. The analyst wants to find all systems that may have executed this file in the past 90 days. The SIEM has ingested endpoint logs, but the file hash is not a standard field in the normalized schema. What is the most efficient next step?

    Select an answer first
  3. 13application · medium

    A company ingests firewall syslog, Windows Event Logs, and cloud audit logs into its SIEM. Analysts complain that searching for a user's activity across all sources requires knowing the exact log format of each source. Which SIEM capability should the administrator verify is correctly configured to resolve this issue?

    Select an answer first
  4. 14application · medium

    A SOC wants to detect lateral movement within the network. Which combination of data sources would provide the most relevant visibility for this detection?

    Select an answer first
  5. 15application · medium

    A SOC manager wants a single view that shows real-time alert volume, top affected assets, and recent high-severity incidents for the team's daily operations. Which SIEM feature should be configured?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.