
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 21
2.21 Determine the Next Action Based on User Behavior Alerts 350-201 Practice Questions (Page 7)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
5concepts
30%of the exam
Questions 31–35
- 31
A security operations center receives three user behavior alerts simultaneously: (1) a marketing user failed to authenticate five times in 10 minutes, (2) a system administrator accessed 50 servers via remote desktop in one hour, and (3) a contractor downloaded 10 GB of source code from a repository they have never accessed before. The organization has a policy that prioritizes data exfiltration risks. Which alert should be investigated first?
Select an answer first - 32
A user behavior alert indicates that an employee has been sending emails with encrypted attachments to an external email address. The employee's role involves sending financial reports to auditors, and the external address is a known auditor's domain. The organization has a policy that requires investigation of any encrypted email sent to external addresses, but does not require automatic blocking. What should the analyst do?
Select an answer first - 33
A user behavior alert flags a database administrator who has been querying the customer database at 3 AM for the past three nights. The administrator has a history of performing maintenance during off-hours, but the queries are SELECT statements that return large result sets. The organization has a policy that requires investigation of any unusual data access, but does not require automatic containment. The administrator is the only person with access to the database. What should the analyst do?
Select an answer first - 34
A user behavior alert shows that a user is downloading a large volume of sensitive customer data to a USB drive. The user has no legitimate business need for this data. What is the most appropriate next action?
Select an answer first - 35
A user behavior alert flags a network administrator who has been logging in from a new VPN endpoint and running configuration commands on routers during off-hours. The administrator has a history of on-call maintenance work and the commands are consistent with scheduled network changes. The organization's policy requires that off-hours administrative activity be monitored but not automatically blocked. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.