Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 21

2.21 Determine the Next Action Based on User Behavior Alerts 350-201 Practice Questions (Page 2)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
30%of the exam

Questions 6–10

  1. 6application · medium

    A user behavior alert indicates that an employee has been accessing a competitor's website from their corporate device during work hours. The employee's role is in research and development. What is the most appropriate next action?

    Select an answer first
  2. 7application · medium

    Your organization has a policy that any user behavior alert involving a privileged account must be escalated to the incident response team within 15 minutes. A privileged user's account triggers an alert for an unusual login time. You have verified that the user is on-call and the login is legitimate. What should you do?

    Select an answer first
  3. 8application · medium

    Your SOC has limited staff and receives two user behavior alerts: (1) a user accessed a sensitive file from a known malicious IP address, and (2) a user attempted to access a restricted server but failed due to permissions. Which alert should you investigate first?

    Select an answer first
  4. 9expert · hard

    A user behavior alert flags that an employee has been accessing a customer database from a new IP address. The employee is in customer support and has legitimate access to the database. The new IP address is in a different country. The employee is not traveling. What should you do?

    Select an answer first
  5. 10application · medium

    A user behavior alert indicates that a finance employee has been accessing the HR payroll database every night for the past week, which is outside their normal job function. The employee's credentials have not been used from unusual locations, and there is no other suspicious activity. The organization's policy requires that any access to sensitive data outside job duties be immediately investigated, but does not require automatic account suspension. What is the most appropriate next action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.