
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 10
2.10 Determine DevSecOps Recommendations (implications) 350-201 Practice Questions (Page 9)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
30%of the exam
Questions 41–45
- 41
A team is shifting left in their CI/CD pipeline. They currently run DAST only after deployment. They want to identify vulnerabilities earlier. Which change would BEST achieve this?
Select an answer first - 42
A security team is implementing automated security testing in a CI/CD pipeline for a web application. They want to catch both code-level vulnerabilities and runtime issues, but they have limited time in the pipeline. Which combination of testing types is most efficient?
Select an answer first - 43
Which practice is essential for securing Infrastructure as Code (IaC) templates?
Select an answer first - 44
A financial services company must enforce a policy that no code containing certain sensitive data patterns (e.g., credit card numbers) is merged into the main branch. They want this to be automated and not rely on developers remembering to run scans. Which approach is most effective?
Select an answer first - 45
Which type of automated security testing analyzes source code without executing it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.