
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 4)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 16–20
- 16
A SIEM analyst is tuning a correlation rule that alerts on failed logins followed by a successful login. The rule generates many false positives due to users mistyping passwords. The analyst wants to reduce false positives without missing real brute-force attacks. Which tuning approach is most effective?
Select an answer first - 17
How does integrating threat intelligence feeds improve a SIEM's detection capability?
Select an answer first - 18
A security operations center (SOC) ingests firewall syslog, Windows Event Logs, and NetFlow into its SIEM. Analysts notice that the same source IP appears in a firewall deny log and a Windows logon failure event, but the SIEM does not correlate them because the IP is stored in different fields. Which SIEM capability should the team verify is correctly configured to enable this correlation?
Select an answer first - 19
A company is deploying a SIEM and must decide whether to collect all logs from all sources or only security-relevant logs. The security team wants maximum visibility, but the budget limits storage and processing. Which approach balances visibility with cost?
Select an answer first - 20
A SIEM correlation rule alerts on 'multiple failed logins followed by a successful login' within 10 minutes. The SOC is overwhelmed by alerts from a single user who frequently forgets their password. The user is a known developer with legitimate access. Which tuning approach best reduces alert fatigue without losing detection of actual brute-force attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.