Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 11

2.11 Describe Use and Concepts Related to Using a Threat Intelligence Platform (TIP) to Automate Intelligence 350-201 Practice Questions (Page 6)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts
30%of the exam

Questions 26–30

  1. 26application · medium

    A SOC wants to automate the dissemination of indicators to their SIEM, firewall, and EDR, but only for indicators that are relevant to their industry. Which TIP feature would allow them to filter indicators based on industry relevance?

    Select an answer first
  2. 27expert · hard

    A multinational company has a TIP that aggregates intelligence from regional feeds. They want to automate the dissemination of indicators to their regional firewalls, but they have different compliance requirements in different regions. Some regions require that certain data not leave the region. What is the best way to handle this?

    Select an answer first
  3. 28application · medium

    A company wants to use its TIP for proactive defense by automatically updating its intrusion prevention system (IPS) with new indicators. However, they are concerned about the risk of blocking legitimate traffic due to false positives. What is the best practice to mitigate this risk while maintaining automation?

    Select an answer first
  4. 29expert · hard

    A security team is implementing a TIP and wants to automate the 'feedback' stage of the intelligence lifecycle. They want to use feedback from incident response to improve future intelligence. What is the best way to achieve this?

    Select an answer first
  5. 30expert · hard

    A company has a TIP integrated with a SIEM and a SOAR. During an incident, the SOC wants to automatically isolate infected hosts based on indicators from the TIP. However, the network team is concerned about isolating critical production servers. Which approach best balances automated response with the network team's concern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.