
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 6
2.6 Determine Patching Recommendations, Given a Scenario 350-201 Practice Questions (Page 1)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
30%of the exam
Questions 1–5
- 1
After applying a security patch to a web application, the security team wants to confirm that the patch was installed correctly and that the vulnerability is mitigated. Which action BEST verifies patch effectiveness?
Select an answer first - 2
A company discovers that its web server is running an outdated version of OpenSSL that is vulnerable to CVE-2022-3786 (buffer overflow). The server is behind a load balancer that terminates TLS, and the server is only accessible internally. What should the company do?
Select an answer first - 3
A security team has identified three vulnerabilities in different systems: one is a critical remote code execution in an internet-facing web server, one is a high-severity privilege escalation in an internal application, and one is a moderate denial-of-service in a non-critical internal tool. Which patch should be applied first?
Select an answer first - 4
A security analyst is reviewing a vulnerability report for a web server. The report indicates that the installed version of Apache HTTP Server is 2.4.49 and that a known remote code execution vulnerability exists in this version. Which step is most important for determining whether the server is actually exposed and needs a patch?
Select an answer first - 5
An organization has three servers with different vulnerabilities: Server A is exposed to the internet and has a critical remote code execution vulnerability with an active exploit; Server B is internal-only and has a high-severity vulnerability but no known exploit; Server C is a development server with a moderate vulnerability. All three have patches available. Which server should be patched first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.