Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 6

3.6 Determine Known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) 350-201 Practice Questions (Page 10)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
11concepts
30%of the exam

Questions 46–50

  1. 46expert · hard

    A security analyst is investigating a potential compromise. The SIEM shows a connection to a known malicious IP address, but the endpoint has no matching file hashes from the threat feed. The analyst suspects the malware may be a new variant. Which action would be most effective to confirm the compromise?

    Select an answer first
  2. 47application · medium

    During incident response, an analyst collects evidence from a compromised host. The analyst finds a suspicious executable, a command-and-control domain in the hosts file, and a registry key that enables persistence. Which set of items are all examples of IOCs?

    Select an answer first
  3. 48expert · hard

    A security analyst is investigating an alert where a known malicious IP address is communicating with an internal server. The SIEM also shows that the server is making unusual outbound connections to multiple internal hosts. The analyst must determine whether this is a coordinated attack. Which action would provide the strongest evidence?

    Select an answer first
  4. 49application · medium

    A company's threat intelligence feed provides a list of known malicious IP addresses and file hashes. The security team wants to detect whether any of these known threats have already affected their environment. Which approach would be most effective?

    Select an answer first
  5. 50application · medium

    An organization's SOC has a list of known malicious IP addresses and also observes a user account making repeated failed login attempts followed by a successful login from a foreign country. The SOC wants to improve detection accuracy. How should the SOC use these two pieces of information together?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.