
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 17
2.17 Describe Use and Concepts of SIEM Tools for Security Data Analytics 350-201 Practice Questions (Page 9)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
30%of the exam
Questions 41–45
- 41
A SOC analyst needs to quickly identify which alerts from the last 24 hours are critical and require immediate action. Which SIEM feature provides the most efficient way to prioritize?
Select an answer first - 42
A SIEM analyst notices that a correlation rule triggers hundreds of alerts per day for a known internal scanning tool. The alerts are consuming investigation time. Which action should the analyst take to reduce noise while preserving detection of genuine malicious scanning?
Select an answer first - 43
How does a SIEM support incident investigation?
Select an answer first - 44
A SIEM analyst wants to prioritize alerts by correlating internal logs with known adversary infrastructure. The team has access to a commercial threat intelligence feed that updates hourly. What is the best way to use this feed in the SIEM?
Select an answer first - 45
During an incident, an analyst needs to understand the full timeline of an attacker's activity, including initial access, lateral movement, and data exfiltration. The SIEM has logs from endpoints, firewalls, and authentication servers. Which investigation feature is most useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.