Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 8

3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 1)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
30%of the exam

Questions 1–5

  1. 1expert · hard

    An employee's laptop was stolen, and the laptop contained sensitive customer data. The company's endpoint protection logs show that the laptop was encrypted, but the employee had also copied some files to a USB drive that was in the laptop bag. The security team must determine whether the data on the USB drive was encrypted. Which investigation step is most appropriate?

    Select an answer first
  2. 2application · medium

    A company's web application allows users to upload files. An investigator suspects that an attacker abused an insecure API endpoint to upload a malicious file that then exfiltrated data. Which log sources should the investigator correlate to confirm the attack?

    Select an answer first
  3. 3expert · hard

    A web application suffered a data breach. The application logs show API calls from multiple IP addresses, but the API gateway logs are incomplete. The investigator must determine the scope of the data loss. Which approach is BEST?

    Select an answer first
  4. 4foundation · easy

    A security analyst is beginning an investigation into a potential data loss incident. According to a structured investigation workflow, which sequence of steps should the analyst follow to ensure a thorough and defensible investigation?

    Select an answer first
  5. 5application · medium

    A cloud storage bucket was found to be publicly readable, and sensitive files were downloaded by unknown parties. The bucket's access logs are enabled. Which evidence should the investigator preserve FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.