Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 21

2.21 Determine the Next Action Based on User Behavior Alerts 350-201 Practice Questions (Page 3)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
30%of the exam

Questions 11–15

  1. 11application · medium

    A user behavior alert indicates that an employee has been logging in from a new device and accessing the HR system, which is not part of their job role. The employee recently changed roles from marketing to operations, and the HR system access is consistent with the new role's responsibilities. What should the analyst do?

    Select an answer first
  2. 12application · medium

    A user behavior alert shows that an employee has been accessing a database containing customer credit card information outside of business hours. The organization is subject to PCI DSS and has a policy that requires immediate containment of any potential cardholder data breach. The employee's credentials have not been used from unusual locations. What should the analyst do?

    Select an answer first
  3. 13expert · hard

    Your SOC receives two user behavior alerts: (1) a junior employee accessed a file share containing financial reports at 2 AM, which is outside their normal hours, and (2) a senior executive accessed the same file share from a new device during business hours. The executive's role requires access to financial reports. You have limited staff. Which alert should you prioritize?

    Select an answer first
  4. 14foundation · easy

    A security operations center receives two user behavior alerts. Alert 1: A user attempted to access a file containing credit card numbers without authorization. Alert 2: A user accessed a public website that is commonly used for personal browsing. Which alert should be prioritized for investigation?

    Select an answer first
  5. 15application · medium

    A user in the finance department who normally works 9 AM–5 PM from the office suddenly authenticates at 2 AM from a foreign IP address and downloads a 2 GB file from a file-sharing site. The user's account has no history of off-hours access or remote access. The organization has a policy that requires immediate containment for any account suspected of compromise. What should the security analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.