Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 25

2.25 Determine the Tactics, Techniques, and Procedures (TTPs) from an Attack 350-201 Practice Questions (Page 5)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
4concepts
30%of the exam

Questions 21–24

  1. 21application · medium

    A security analyst is reviewing logs from a compromised workstation. The logs show that a user received a spear-phishing email with a malicious macro-enabled document. After opening the document, a PowerShell command executed that downloaded and ran a remote script. The script then created a scheduled task to maintain persistence. Which sequence of MITRE ATT&CK tactics best matches this attack chain?

    Select an answer first
  2. 22expert · hard

    A security team is investigating a sophisticated attack. The attacker used a zero-day exploit in a web browser to gain initial access. After gaining access, the attacker used a PowerShell script to download and execute a C2 agent. The C2 agent then used a legitimate cloud storage service (e.g., Dropbox) for command and control. The team needs to document the TTPs. Which technique is most appropriate for the use of cloud storage for C2?

    Select an answer first
  3. 23application · medium

    A security analyst is reviewing a web server access log. The log shows a request to '/admin/login.php' with a POST parameter containing a long string of SQL commands. The response was a 200 OK with an error message revealing database table names. The analyst needs to identify the TTP. Which MITRE ATT&CK technique is most clearly indicated?

    Select an answer first
  4. 24application · medium

    A security analyst is categorizing an attack where an attacker used a phishing email to deliver a malicious attachment. The attachment, when opened, executed a PowerShell script that downloaded a second-stage payload. The payload then established persistence by creating a Windows service. Which combination of MITRE ATT&CK tactics is most directly observed?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 350-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.