
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 6
2.6 Determine Patching Recommendations, Given a Scenario 350-201 Practice Questions (Page 3)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
30%of the exam
Questions 11–15
- 11
After applying a patch to a web application, the security team wants to confirm that the patch is effective and that the application is not broken. Which action BEST verifies patch effectiveness?
Select an answer first - 12
A company has three critical vulnerabilities to patch: (1) a remote code execution in a public-facing web server, (2) a privilege escalation in an internal HR application, and (3) a denial-of-service in a non-critical internal tool. The web server is exposed to the internet, the HR application is only accessible internally, and the internal tool is used by a small team. Which patch should be applied FIRST?
Select an answer first - 13
A patch is available for a critical vulnerability in a database server. The patch is known to be incompatible with the current version of the database management system. What should the administrator do first?
Select an answer first - 14
A company operates a hybrid environment with a public-facing web server and an internal database server. The web server has a critical vulnerability with an active exploit in the wild, but the patch requires a reboot that will cause a 10-minute outage. The database server has a high-severity vulnerability with no known exploit, and its patch requires a reboot that will cause a 2-hour outage because of data migration. The web server is business-critical and cannot be down during peak hours, while the database server can be down during off-peak hours. What should the security team do?
Select an answer first - 15
A company has three servers with the following vulnerabilities: (1) a public-facing web server with a critical RCE, (2) an internal file server with a high-severity privilege escalation, and (3) a development server with a medium-severity DoS. The company has limited patching resources and can only patch one server this week. Which server should be patched FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.