Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 21

2.21 Determine the Next Action Based on User Behavior Alerts 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    A user behavior alert shows that an employee has been logging in from multiple geographic locations within a short time period. The employee is not traveling. What is the most likely interpretation of this alert?

    Select an answer first
  2. 17application · medium

    A user in the finance department who normally works 9 AM to 5 PM has just authenticated to a file server at 2 AM from an IP address that is on the company's threat intelligence blocklist. The user has no history of remote access. Which action should you take first?

    Select an answer first
  3. 18expert · hard

    A user behavior alert flags a system administrator who has been logging in from a new VPN endpoint and running commands to disable security logging on multiple servers. The administrator has a history of performing maintenance during off-hours, but has never disabled security logging before. The organization has a policy that requires immediate containment for any activity that could disable security controls. However, the administrator is currently on-call and may be performing legitimate maintenance. What should the analyst do?

    Select an answer first
  4. 19application · medium

    A user behavior alert indicates that an employee has been sending emails with attachments to a personal email address every Friday for a month. The attachments are small and the employee's role involves sharing reports with external partners. The organization's policy requires that any data sent to personal email addresses be investigated, but does not require automatic blocking. What is the most appropriate next action?

    Select an answer first
  5. 20foundation · easy

    A security analyst reviews a user behavior alert indicating that a user account has downloaded 500 GB of data from a file share in the last hour, while the user's historical baseline shows an average of 2 GB per day. What is the most appropriate first step for the analyst to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.