Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 5

3.5 Determine the Steps to Investigate Potential Endpoint Intrusion Across a Variety of Platform Types Such as Desktop, Laptop, IoT, Mobile Devices 350-201 Practice Questions (Page 4)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
30%of the exam

Questions 16–20

  1. 16foundation · easy

    Which remediation step is most appropriate after confirming that a specific malware binary was found on an endpoint?

    Select an answer first
  2. 17application · medium

    During an investigation of a Windows laptop, the analyst finds a suspicious PowerShell script in the user's Downloads folder. The script contains a command that downloads an executable from an external IP and runs it. Which analysis technique would best confirm whether the executable executed and what it did?

    Select an answer first
  3. 18expert · hard

    An analyst is investigating a potential intrusion that involved a phishing email sent to multiple users. The analyst finds that one user clicked the link and entered credentials on a fake login page. The analyst also finds that the same credentials were used to log into the corporate VPN from an external IP. Which conclusion is most supported by the evidence?

    Select an answer first
  4. 19expert · hard

    An analyst is investigating a potential intrusion on a Windows server that runs a critical application. The analyst has limited time because the server must be restored to service quickly. The analyst finds a suspicious scheduled task that runs a PowerShell script. Which action best balances the need for evidence preservation and business continuity?

    Select an answer first
  5. 20application · medium

    A security analyst is examining a Windows workstation suspected of malware infection. The analyst finds a suspicious executable in the user's AppData folder and wants to determine if it has persistence mechanisms. Which analysis technique would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.