
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 8
3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 5)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
30%of the exam
Questions 21–25
- 21
A server administrator discovers that a file share was accessed by an unauthorized user, and a large number of files were copied. The server logs show that the unauthorized user used a valid account, but the account's password was recently changed. The security team must determine whether the account was compromised or if the user was an insider. Which investigation step is most appropriate?
Select an answer first - 22
A security analyst is investigating a potential data loss incident where an employee emailed a spreadsheet of customer data to a personal email address. The email gateway logs show the message was sent, but the analyst needs to confirm the file was actually attached. Which step should the analyst take NEXT in the investigation workflow?
Select an answer first - 23
An endpoint was used to exfiltrate data via email and USB. The device is a laptop that is currently in sleep mode. The investigator must decide whether to perform live forensics or shut down the laptop and create a forensic image. The laptop is encrypted with BitLocker, and the investigator has the recovery key. Which approach is MOST appropriate?
Select an answer first - 24
During a data loss investigation, an analyst collects logs from multiple sources and stores them on a USB drive. The analyst then uses the same USB drive to transfer the logs to a forensic workstation. Which practice is MOST important to maintain the integrity of the evidence?
Select an answer first - 25
An application security analyst is investigating a data loss incident involving a web application. Which application vector is most commonly associated with data exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.