
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 5
3.5 Determine the Steps to Investigate Potential Endpoint Intrusion Across a Variety of Platform Types Such as Desktop, Laptop, IoT, Mobile Devices 350-201 Practice Questions (Page 5)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
6concepts
30%of the exam
Questions 21–25
- 21
Which analysis technique is most useful for identifying a previously unknown malware binary on an endpoint?
Select an answer first - 22
During an incident, a security analyst finds that a user's laptop has a Trojan, and the same user's smartphone has an app that communicates with the same external IP address. What should the analyst do to build a comprehensive picture of the intrusion?
Select an answer first - 23
Which method is appropriate for preserving evidence from a mobile device that is powered on?
Select an answer first - 24
After investigating a phishing incident that compromised several employee laptops, the security team has identified the malware and its entry point. What should be included in the final report to guide remediation?
Select an answer first - 25
Which source of information is most useful for correlating an intrusion across multiple endpoints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.