Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 5

3.5 Determine the Steps to Investigate Potential Endpoint Intrusion Across a Variety of Platform Types Such as Desktop, Laptop, IoT, Mobile Devices 350-201 Practice Questions (Page 6)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
6concepts
30%of the exam

Questions 26–30

  1. 26foundation · easy

    What is the primary purpose of the final report in an endpoint intrusion investigation?

    Select an answer first
  2. 27application · medium

    After investigating a compromised desktop, the analyst determines that the attacker used a known vulnerability in a third-party application to gain access. The analyst has collected evidence and identified the scope of the intrusion. What should the analyst include in the remediation recommendations?

    Select an answer first
  3. 28expert · hard

    After a thorough investigation, an analyst determines that an attacker compromised a user's laptop via a phishing email and used the compromised account to access a file server. The analyst has identified the scope and collected evidence. Which remediation plan best addresses the root cause and prevents recurrence?

    Select an answer first
  4. 29application · medium

    An analyst is investigating a series of failed login attempts on a corporate VPN. The analyst finds that the attempts originated from a single external IP address and targeted multiple user accounts. Which additional data source would best help determine if any of the accounts were successfully compromised?

    Select an answer first
  5. 30application · medium

    After investigating a compromised mobile device, the analyst determines that the device was jailbroken and a malicious app was installed. The analyst has collected evidence and identified the scope. What should the analyst recommend as the primary remediation step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.