Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 8

3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 3)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
8concepts
30%of the exam

Questions 11–15

  1. 11application · medium

    A web application allows users to upload files. The application logs show that a user uploaded a file that contained a script, and the script was executed on the server. The security team suspects that the application failed to validate the file type. Which investigation step is most appropriate to determine the scope of the data loss?

    Select an answer first
  2. 12application · medium

    An organization discovers that customer data was exfiltrated from a cloud database. The investigation team has access to CloudTrail logs, database audit logs, and VPC flow logs. Which correlation would BEST identify the scope of the data loss?

    Select an answer first
  3. 13expert · hard

    A company uses a multi-cloud environment with AWS S3 and an Azure SQL database. An alert indicates that customer data was exfiltrated. The investigation team has limited time and must preserve evidence while minimizing production impact. CloudTrail is enabled in AWS, and Azure SQL audit logs are enabled. The team suspects either a misconfigured S3 bucket or a SQL injection in the Azure database. Which approach BEST balances evidence preservation with production continuity?

    Select an answer first
  4. 14expert · hard

    A security analyst is investigating a data loss incident that involves a user's endpoint, a file server, and a cloud storage service. The analyst has collected logs from all three sources, but the logs show different timestamps because the systems are in different time zones. The analyst must determine the sequence of events. Which step is most appropriate?

    Select an answer first
  5. 15foundation · easy

    During a data loss investigation, an analyst has completed the detection and scoping phase. What is the next step in the investigation workflow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.