Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 4Objective 5

4.5 Determine Opportunities for Automation, Orchestration, and Machine Learning Within a SOAR Platform 350-201 Practice Questions (Page 2)

Part of the Automation domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)

15questions here
3free pages
7concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    A security team wants to use machine learning to improve their SOAR platform's ability to prioritize incidents. They have historical data on past incidents, including the final outcome (true positive vs. false positive). Which ML approach would best enable the SOAR platform to automatically prioritize new incidents?

    Select an answer first
  2. 7application · medium

    A SOC team manually reviews firewall logs each morning to identify failed login attempts from external IPs. They then cross-reference the IPs with a threat intelligence feed and block the malicious ones. This process takes two hours daily. What is the most effective automation opportunity?

    Select an answer first
  3. 8application · medium

    A security operations team receives hundreds of daily alerts from their EDR, most of which are false positives triggered by legitimate software updates. Analysts manually review each alert, check the hash against a threat intel feed, and close it. The team wants to reduce analyst workload without risking missed true positives. Which approach best applies SOAR automation to this scenario?

    Select an answer first
  4. 9application · medium

    A company uses separate tools for ticketing, threat intelligence, and endpoint response. When an incident is confirmed, analysts manually copy indicators from the threat intel portal, create a ticket, and then run containment commands on the affected endpoints. The team wants to streamline this process. What is the most effective use of SOAR orchestration?

    Select an answer first
  5. 10expert · hard

    A security team is evaluating two processes for automation: (1) blocking malicious IPs from firewall logs, which occurs 500 times per month and takes 5 minutes each, and (2) investigating a complex multi-stage attack, which occurs 5 times per month and takes 4 hours each. The team has limited development resources. Which process should they prioritize for automation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.