
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 8
3.8 Determine the Steps to Investigate Potential Data Loss from a Variety of Vectors of Modality Such as Cloud, Endpoint, Server, Databases, Application 350-201 Practice Questions (Page 9)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
30%of the exam
Questions 41–45
- 41
A database administrator discovers that a table containing customer PII was exported to a CSV file, but no one in the organization admits to performing the export. The database audit logs show a series of SQL queries that appear to be injection attempts. Which investigation step is most appropriate to determine whether the export was caused by SQL injection?
Select an answer first - 42
A file server has a shared folder that was accidentally configured with 'Everyone' full control. An investigator needs to determine if any data was actually accessed by unauthorized users. Which log source would provide the most direct evidence?
Select an answer first - 43
An endpoint detection and response (EDR) alert shows that a user copied a large number of files to a removable drive. The user claims they were backing up their work. The security team needs to determine whether the files were sensitive. Which data source should the investigator examine?
Select an answer first - 44
A database administrator discovers that a table containing credit card numbers was exported, but the database audit logs do not show any direct export queries. The administrator suspects that the data was exfiltrated through a SQL injection vulnerability in a web application. The web application logs are available, but they are not correlated with the database logs. Which investigation step is most appropriate?
Select an answer first - 45
A server administrator notices that a configuration file for a web server was modified, and the server is now serving files from an unexpected directory. The administrator suspects that an attacker exploited a vulnerability to change the configuration. Which investigation step is most appropriate to determine the scope of the data loss?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.