Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 7

3.7 Determine IOCs in a Sandbox Environment (includes Generating Complex Indicators) 350-201 Practice Questions (Page 1)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A sandbox report for a trojan shows that it modifies the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' to add a value named 'Updater', and then communicates with the domain 'update-check.example.com'. The analyst wants to create a complex indicator that detects this trojan on other hosts. Which indicator would be most effective?

    Select an answer first
  2. 2expert · hard

    A security team is analyzing a banking trojan that uses a legitimate code-signing certificate to sign its executable. The sandbox report shows the trojan modifies the browser's proxy settings and injects code into the browser process. The team wants to create a detection rule that is effective but has low false positives. Which rule is best?

    Select an answer first
  3. 3application · medium

    A sandbox report for a ransomware sample shows that it encrypts files with a specific extension and leaves a ransom note. The report also shows the ransomware creates a mutex and connects to an IP address. Which IOC is most likely to be unique to this ransomware family?

    Select an answer first
  4. 4expert · hard

    A sandbox report shows a sample that creates a file named 'update.exe' in the Temp folder, modifies the 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' registry key, and then connects to a domain that is categorized as 'newly seen' by the threat intelligence feed. The analyst must decide which IOCs to prioritize for immediate action. What is the best decision?

    Select an answer first
  5. 5application · medium

    A sandbox report shows a binary attempting to connect to an IP address that is not on any threat intelligence blocklist. The binary also drops a file named 'update.dll' and creates a service named 'Windows Update Service'. What should the analyst do to validate the IP as an IOC?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.