Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 6

2.6 Determine Patching Recommendations, Given a Scenario 350-201 Practice Questions (Page 5)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts
30%of the exam

Questions 21–25

  1. 21application · medium

    A company runs a critical database server that cannot be rebooted during business hours. The vendor released a security patch that requires a reboot. The patch addresses a vulnerability that is not currently being exploited in the wild. What should the administrator do?

    Select an answer first
  2. 22application · medium

    A vulnerability scanner reports that a web application is running an outdated version of a content management system (CMS) with a known SQL injection vulnerability. The CMS vendor has released a security patch, but the application is heavily customized and the patch may break custom modules. What should the security team do first?

    Select an answer first
  3. 23application · medium

    A hospital's patient-monitoring system runs on a legacy operating system that is no longer supported by the vendor. A critical vulnerability has been disclosed for this OS, but the system cannot be taken offline during patient care hours. What should the security team recommend?

    Select an answer first
  4. 24expert · hard

    A vulnerability report indicates that a server is running an outdated version of an application that is vulnerable to a cross-site scripting (XSS) attack. The application is behind a web application firewall (WAF) that filters XSS payloads. The vendor has released a patch, but the patch requires a reboot and the server is a domain controller. What should the administrator do?

    Select an answer first
  5. 25application · medium

    A company's industrial control system (ICS) runs on a legacy Windows version that is no longer supported. A critical vulnerability is disclosed, but the ICS cannot be rebooted without halting production. What should the company do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.