Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 6

2.6 Determine Patching Recommendations, Given a Scenario 350-201 Practice Questions (Page 3)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts
30%of the exam

Questions 11–15

  1. 11application · medium

    After applying a patch to a web application, the security team wants to confirm that the patch is effective and that the application is not broken. Which action BEST verifies patch effectiveness?

    Select an answer first
  2. 12application · medium

    A company has three critical vulnerabilities to patch: (1) a remote code execution in a public-facing web server, (2) a privilege escalation in an internal HR application, and (3) a denial-of-service in a non-critical internal tool. The web server is exposed to the internet, the HR application is only accessible internally, and the internal tool is used by a small team. Which patch should be applied FIRST?

    Select an answer first
  3. 13foundation · easy

    A patch is available for a critical vulnerability in a database server. The patch is known to be incompatible with the current version of the database management system. What should the administrator do first?

    Select an answer first
  4. 14expert · hard

    A company operates a hybrid environment with a public-facing web server and an internal database server. The web server has a critical vulnerability with an active exploit in the wild, but the patch requires a reboot that will cause a 10-minute outage. The database server has a high-severity vulnerability with no known exploit, and its patch requires a reboot that will cause a 2-hour outage because of data migration. The web server is business-critical and cannot be down during peak hours, while the database server can be down during off-peak hours. What should the security team do?

    Select an answer first
  5. 15application · medium

    A company has three servers with the following vulnerabilities: (1) a public-facing web server with a critical RCE, (2) an internal file server with a high-severity privilege escalation, and (3) a development server with a medium-severity DoS. The company has limited patching resources and can only patch one server this week. Which server should be patched FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.