
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 5)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 21–25
- 21
A SIEM receives logs from a custom application that records timestamps in a non-standard format. The security team notices that correlation rules that depend on event time are not working correctly. What is the most likely cause?
Select an answer first - 22
A SIEM correlation rule is designed to detect a brute-force attack by counting failed logins from a single source IP. The rule is not firing even though the attack is occurring. Which of the following is the most likely cause?
Select an answer first - 23
What is the purpose of log normalization in a SIEM?
Select an answer first - 24
Which function is a core capability of a SIEM tool?
Select an answer first - 25
A SOC wants to prioritize alerts based on the reputation of external IPs involved. Which SIEM capability should be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.