Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 11

2.11 Describe Use and Concepts Related to Using a Threat Intelligence Platform (TIP) to Automate Intelligence 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts
30%of the exam

Questions 16–20

  1. 16foundation · easy

    Which activity is a common use case for a Threat Intelligence Platform (TIP)?

    Select an answer first
  2. 17expert · hard

    A security operations center uses a TIP to automate the dissemination of indicators to its EDR and firewall. They notice that the EDR is receiving too many alerts, causing alert fatigue. They want to reduce the noise while still maintaining effective detection. What is the best approach?

    Select an answer first
  3. 18application · medium

    A small security team is considering investing in a TIP. They currently receive threat intelligence from several open-source feeds and a commercial feed, but they struggle to correlate the data and identify relevant threats. Which benefit of a TIP directly addresses this challenge?

    Select an answer first
  4. 19expert · hard

    A company has a TIP integrated with its SIEM and SOAR. They want to automate blocking of malicious domains on their DNS firewall, but they are concerned about the impact on business operations if a legitimate domain is blocked. They also want to ensure that the response is consistent across all locations. What is the best way to achieve this?

    Select an answer first
  5. 20expert · hard

    A security team is configuring a TIP to automate the ingestion of indicators from multiple sources. They notice that some sources provide indicators with low confidence scores, and they want to avoid overwhelming their SIEM with low-value data. They also need to ensure that important indicators are not missed. What is the best configuration strategy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.