Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 6

2.6 Determine Patching Recommendations, Given a Scenario 350-201 Practice Questions (Page 1)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    After applying a security patch to a web application, the security team wants to confirm that the patch was installed correctly and that the vulnerability is mitigated. Which action BEST verifies patch effectiveness?

    Select an answer first
  2. 2application · medium

    A company discovers that its web server is running an outdated version of OpenSSL that is vulnerable to CVE-2022-3786 (buffer overflow). The server is behind a load balancer that terminates TLS, and the server is only accessible internally. What should the company do?

    Select an answer first
  3. 3foundation · easy

    A security team has identified three vulnerabilities in different systems: one is a critical remote code execution in an internet-facing web server, one is a high-severity privilege escalation in an internal application, and one is a moderate denial-of-service in a non-critical internal tool. Which patch should be applied first?

    Select an answer first
  4. 4foundation · easy

    A security analyst is reviewing a vulnerability report for a web server. The report indicates that the installed version of Apache HTTP Server is 2.4.49 and that a known remote code execution vulnerability exists in this version. Which step is most important for determining whether the server is actually exposed and needs a patch?

    Select an answer first
  5. 5application · medium

    An organization has three servers with different vulnerabilities: Server A is exposed to the internet and has a critical remote code execution vulnerability with an active exploit; Server B is internal-only and has a high-severity vulnerability but no known exploit; Server C is a development server with a moderate vulnerability. All three have patches available. Which server should be patched first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.