Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 25

2.25 Determine the Tactics, Techniques, and Procedures (TTPs) from an Attack 350-201 Practice Questions (Page 1)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst is examining a compromised host. The evidence shows that an attacker used a legitimate remote desktop protocol (RDP) connection to access the host, then disabled the Windows Defender firewall, and finally used a built-in Windows utility (certutil) to download a malicious executable. Which MITRE ATT&CK technique is best associated with the use of certutil?

    Select an answer first
  2. 2foundation · easy

    When mapping an observed attacker behavior to MITRE ATT&CK, which of the following is the correct approach?

    Select an answer first
  3. 3application · medium

    A security team is documenting an attack where the attacker used a spear-phishing email with a malicious attachment to gain initial access. After execution, the attacker used a PowerShell script to enumerate the local network and then used RDP to move to another host. Which MITRE ATT&CK tactic is the PowerShell enumeration most directly associated with?

    Select an answer first
  4. 4application · medium

    During an incident, you find that an attacker used a legitimate remote monitoring and management (RMM) tool to access a workstation remotely. The RMM tool was installed silently using a compromised admin account. Which MITRE ATT&CK technique is most directly demonstrated by the use of the RMM tool?

    Select an answer first
  5. 5application · medium

    An analyst is reviewing Windows event logs from a compromised server. The logs show that a user account was created and added to the local administrators group. The analyst also sees that the new account was used to schedule a task that runs a script every hour. Which two MITRE ATT&CK techniques are most clearly indicated?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.