
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 7
3.7 Determine IOCs in a Sandbox Environment (includes Generating Complex Indicators) 350-201 Practice Questions (Page 6)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
30%of the exam
Questions 26–30
- 26
After analyzing a ransomware sample in a sandbox, the report shows the sample encrypts files with a specific extension, drops a ransom note named 'README.txt', and attempts to connect to an IP address that is listed in the organization's threat intelligence feed as a known C2 server. Which set of IOCs should the analyst prioritize for immediate blocking?
Select an answer first - 27
In a sandbox report, which of the following would be considered an IOC?
Select an answer first - 28
Which of the following is an example of a network connection that a sandbox would record during dynamic analysis?
Select an answer first - 29
Why is it beneficial to correlate sandbox outputs with threat intelligence?
Select an answer first - 30
Which characteristic is essential for a sandbox environment used in malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.