
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 6
3.6 Determine Known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) 350-201 Practice Questions (Page 9)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
11concepts
30%of the exam
Questions 41–45
- 41
A security team wants to improve its detection of both known malware and novel attack techniques. The team has limited analyst time and wants to reduce false positives. Which strategy best balances IOC and IOA usage?
Select an answer first - 42
An analyst discovers a file hash that matches a known malware sample on an endpoint. In the context of threat detection, how is this file hash best classified?
Select an answer first - 43
What is a common limitation of using Indicators of Attack (IOAs) for threat detection?
Select an answer first - 44
An analyst is reviewing a list of known malicious indicators to check against endpoint data. Which item would be considered an IOC?
Select an answer first - 45
A security team needs to build a detection capability for a new campaign that uses a unique domain and a specific privilege escalation technique. The team has access to a commercial threat intelligence feed, internal security logs, and incident response reports from other organizations. Which combination of sources would provide the most complete and actionable intelligence for both IOCs and IOAs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.