
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 11
2.11 Describe Use and Concepts Related to Using a Threat Intelligence Platform (TIP) to Automate Intelligence 350-201 Practice Questions (Page 3)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
30%of the exam
Questions 11–15
- 11
Which stage of the intelligence lifecycle involves converting raw data into a format that can be analyzed?
Select an answer first - 12
Which set of functions is typically performed by a Threat Intelligence Platform (TIP)?
Select an answer first - 13
A threat hunting team wants to use the TIP to proactively search for indicators of compromise (IOCs) in their environment. They have a large number of IOCs from multiple sources. What is the most efficient way to use the TIP for this purpose?
Select an answer first - 14
A company uses a TIP to ingest indicators from multiple sources. They want to automatically push high-confidence indicators to their firewall and EDR, but only after a security analyst approves them. Which TIP workflow configuration best meets this requirement?
Select an answer first - 15
A SOC wants to automate the creation of tickets and the blocking of malicious IPs when a high-severity indicator is received. They have a TIP, a SIEM, and a SOAR platform. What is the most effective way to orchestrate this workflow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.