Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 17

2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 5)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts
30%of the exam

Questions 21–25

  1. 21application · medium

    A SIEM receives logs from a custom application that records timestamps in a non-standard format. The security team notices that correlation rules that depend on event time are not working correctly. What is the most likely cause?

    Select an answer first
  2. 22application · medium

    A SIEM correlation rule is designed to detect a brute-force attack by counting failed logins from a single source IP. The rule is not firing even though the attack is occurring. Which of the following is the most likely cause?

    Select an answer first
  3. 23foundation · easy

    What is the purpose of log normalization in a SIEM?

    Select an answer first
  4. 24foundation · easy

    Which function is a core capability of a SIEM tool?

    Select an answer first
  5. 25application · medium

    A SOC wants to prioritize alerts based on the reputation of external IPs involved. Which SIEM capability should be configured?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.