Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 7

3.7 Determine IOCs in a Sandbox Environment (includes Generating Complex Indicators) 350-201 Practice Questions (Page 4)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    An analyst is analyzing a malicious executable in a sandbox. The sandbox report shows that the executable modifies the Windows registry, creates a new file in the AppData folder, and makes an outbound connection to a remote server. Which sandbox feature is most important for capturing the outbound connection's destination?

    Select an answer first
  2. 17application · medium

    A malware sample is known to check for the presence of a debugger and terminate if one is detected. The analyst wants to observe the malware's full behavior in the sandbox. Which sandbox configuration is most appropriate?

    Select an answer first
  3. 18application · medium

    A sandbox report for a malicious document shows that it uses a macro to download a second-stage payload from 'http://malicious.example.com/payload.exe'. The payload then creates a file named 'svchost.exe' in the user's AppData folder. The analyst wants to identify IOCs that can be used to detect this activity across the network. Which IOCs should be recorded?

    Select an answer first
  4. 19application · medium

    A security analyst needs to analyze a suspicious executable that is known to detect virtual machines and refuse to run in sandbox environments. Which sandbox configuration is most likely to help the analyst observe the malware's behavior?

    Select an answer first
  5. 20application · medium

    A security team needs to analyze a suspicious executable that is known to detect virtual machines and refuse to run in sandbox environments. The team wants to obtain useful behavioral IOCs. Which approach should they take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.