
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 8
3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 8)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
30%of the exam
Questions 36–40
- 36
An organization suspects that a cloud storage bucket was accessed by an unauthorized party. Which investigation step is most appropriate to determine the cause?
Select an answer first - 37
A security analyst is investigating a data loss incident where a user's credentials were used to access a file share and download sensitive files. The analyst has collected the authentication logs and the file share access logs. Which step should the analyst take next in the investigation workflow?
Select an answer first - 38
Which investigation step is most effective for detecting unauthorized access to a server?
Select an answer first - 39
A database administrator is investigating a potential data loss incident. Which database vector is most commonly associated with data exfiltration?
Select an answer first - 40
A database was compromised via SQL injection, and the attacker exported a large volume of data. The database is in production and cannot be stopped. The investigator must preserve evidence while maintaining availability. Which combination of actions is MOST appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.