
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 6
3.6 Determine Known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) 350-201 Practice Questions (Page 1)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
11concepts
30%of the exam
Questions 1–5
- 1
A SOC team is implementing a new behavioral analytics tool. The tool flags a sequence of events: a user logs in from a new country, then attempts to access a sensitive database, and then tries to escalate privileges. The user is a remote employee who frequently travels. How should the team handle this alert to balance security and operational impact?
Select an answer first - 2
A security architect is designing a detection strategy for a financial institution. The strategy must detect both known malware and zero-day attacks. The team has limited resources and must prioritize one approach. Which approach best balances the need to detect both types of threats?
Select an answer first - 3
A security manager is deciding whether to invest more in IOC-based detection or IOA-based detection. The organization has a mature IOC program but has experienced several incidents where attackers used novel techniques that evaded detection. The manager wants to reduce the risk of missing new attacks. Which consideration should guide the decision?
Select an answer first - 4
An organization's detection strategy relies on matching file hashes from a threat intelligence feed. A sophisticated attacker uses a known malware family but modifies the binary to change its hash. What is the most effective way to improve detection against this type of evasion?
Select an answer first - 5
A security analyst notices a user account that normally logs in during business hours is now logging in at 3 AM and attempting to access sensitive files. Which type of indicator does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.