
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 8
3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 7)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
30%of the exam
Questions 31–35
- 31
A Linux file server has an unusual number of failed SSH logins followed by a successful login from an unrecognized IP, and then several files were deleted. The server is still running. Which step should be part of the investigation workflow?
Select an answer first - 32
A server experienced a data breach. The server hosts a critical application and cannot be taken offline for more than 30 minutes. The investigator needs to collect evidence while minimizing downtime. Which evidence collection strategy is BEST?
Select an answer first - 33
A server administrator notices that a large number of files in a shared network folder have been renamed to include a '.encrypted' extension. The server logs show an unusual login from an account that has not been used in months. The administrator suspects ransomware. Which step should be taken first to investigate the potential data loss?
Select an answer first - 34
An employee reports that a USB drive containing sensitive customer data was lost. The endpoint security logs show that the USB drive was used on the employee's laptop, but the logs do not show which files were copied. The company requires a full investigation to determine the scope of the data loss. Which action should the investigator take next?
Select an answer first - 35
A company uses a multi-cloud environment with AWS and Azure. An investigation reveals that a storage bucket in AWS and a storage container in Azure both contain sensitive data that was accessed by an external party. The security team must determine the scope of the data loss, but the logs are stored in different formats and locations. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.