Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 5

3.5 Determine the Steps to Investigate Potential Endpoint Intrusion Across a Variety of Platform Types Such as Desktop, Laptop, IoT, Mobile Devices 350-201 Practice Questions (Page 3)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
30%of the exam

Questions 11–15

  1. 11application · medium

    An analyst is investigating a phishing email that was opened on a corporate laptop. The email contained a link to a malicious website. The analyst finds that the laptop's DNS cache shows a query for the malicious domain, but no malware was detected on the laptop. Which additional data source would best help determine if the intrusion spread to other endpoints?

    Select an answer first
  2. 12foundation · easy

    Which system artifact is most commonly examined to identify persistence mechanisms on a Windows desktop?

    Select an answer first
  3. 13application · medium

    An analyst is examining a Linux server that was compromised. The analyst finds a suspicious process running from /tmp and wants to determine if it is malicious. Which analysis technique would provide the most useful evidence?

    Select an answer first
  4. 14application · medium

    A security analyst is investigating a suspected intrusion on an employee's Windows laptop. The laptop is currently powered on and the user is logged in. The analyst needs to preserve volatile data before any further action. Which step should the analyst perform first?

    Select an answer first
  5. 15application · medium

    A security analyst is investigating a potential intrusion on a Linux server that hosts a web application. The analyst suspects that an attacker exploited a web vulnerability to upload a webshell. Which set of artifacts should the analyst examine to confirm the webshell and its activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.