Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 7

3.7 Determine IOCs in a Sandbox Environment (includes Generating Complex Indicators) 350-201 Practice Questions (Page 5)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts
30%of the exam

Questions 21–25

  1. 21application · medium

    A security analyst is analyzing a suspicious executable in a sandbox. The sandbox report shows the executable creates a service named 'LegitService', sets it to auto-start, and then makes an HTTP request to a URL that includes a unique user-agent string. The analyst wants to create a detection rule for the organization's EDR. Which rule would be most effective?

    Select an answer first
  2. 22foundation · easy

    Which of the following is a common IOC that can be extracted from a sandbox report?

    Select an answer first
  3. 23application · medium

    A sandbox analysis of a downloaded file reveals that it contacts an IP address that is not in the organization's threat intelligence feed. The analyst checks the IP's reputation using a public service and finds it is associated with a known exploit kit. The file also creates a scheduled task named 'SystemCheck'. What should the analyst do to create a robust IOC set?

    Select an answer first
  4. 24application · medium

    A sandbox report for a PDF file shows that it spawns a child process (cmd.exe) that executes 'whoami' and then makes an HTTP POST to a known malicious IP. Which combination of IOCs should be used to create a detection rule?

    Select an answer first
  5. 25expert · hard

    A security team is analyzing a fileless attack that uses PowerShell to inject code into a legitimate process (notepad.exe). The sandbox report shows the PowerShell script downloads a payload from a URL and then injects it into notepad.exe. The team wants to create a detection rule that is effective but has low false positives. Which rule is best?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.