Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 25

2.25 Determine the Tactics, Techniques, and Procedures (TTPs) from an Attack 350-201 Practice Questions (Page 3)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts
30%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is investigating a breach where an attacker used a phishing email to deliver a malicious macro. The macro executed PowerShell to download a C2 agent. The agent then used a legitimate Windows utility (bitsadmin) to download additional tools. The attacker also used a previously compromised domain admin account to access multiple servers via SMB. The team needs to document the TTPs in a way that prioritizes the most critical actions. Which TTP should be documented as the primary technique for the initial access?

    Select an answer first
  2. 12application · medium

    An incident responder is analyzing a host that was compromised via a malicious USB device. The USB device presented itself as a keyboard and typed commands to open a PowerShell console and download a payload. The payload then established persistence by modifying the registry run key. Which MITRE ATT&CK technique is NOT directly observed?

    Select an answer first
  3. 13application · medium

    During a threat hunt, you notice that a user account was used to create a new local administrator account on multiple workstations. The account creation was followed by a scheduled task that ran a script to exfiltrate data to an external IP. Which two MITRE ATT&CK tactics are primarily demonstrated?

    Select an answer first
  4. 14foundation · easy

    An analyst observes that an attacker used a spearphishing email to deliver a malicious attachment, which then executed a script to download a remote access tool. In categorizing this behavior, which of the following is the 'procedure'?

    Select an answer first
  5. 15application · medium

    A security analyst is examining a memory dump from a compromised server. The analysis reveals that a process injected code into another legitimate process (e.g., explorer.exe). The injected code then made a network connection to an external IP address. Which MITRE ATT&CK technique is most directly indicated by the process injection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.