Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 8

3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 2)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
30%of the exam

Questions 6–10

  1. 6application · medium

    A user reports that sensitive files were copied to a USB drive from their corporate laptop. The laptop is still powered on and the user is still logged in. Which action should the investigator take FIRST to preserve evidence?

    Select an answer first
  2. 7application · medium

    A cloud administrator discovers that a storage bucket in Azure was configured with public access and contained a backup of a customer database. The administrator suspects that the public access was enabled by an insider. Which evidence source is most useful to determine who enabled public access?

    Select an answer first
  3. 8application · medium

    A company's customer relationship management (CRM) application allows users to export contact lists. The application logs show that a user exported a large list of contacts, but the user claims they only exported a small subset. The security team suspects that the application's API is being abused to bypass the user interface limits. Which investigation step is most appropriate?

    Select an answer first
  4. 9foundation · easy

    An endpoint security analyst is investigating a data loss incident involving a user's workstation. Which endpoint vector is most commonly associated with data exfiltration?

    Select an answer first
  5. 10application · medium

    An application allows users to export reports. A security analyst suspects that a malicious insider used the application's API to export a large volume of customer data. Which combination of log sources would provide the strongest evidence of the insider's actions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.