
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 2
1.2 Determine the Tools Needed Based on a Playbook Scenario 350-201 Practice Questions (Page 2)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
20%of the exam
Questions 6–10
- 6
A playbook for a malware outbreak requires the incident responder to isolate an infected workstation from the network while preserving the ability to collect forensic evidence from the host. Which tool category should the responder use to perform the isolation?
Select an answer first - 7
A security operations center is executing a playbook for a suspected data exfiltration incident. The playbook requires the analyst to (1) identify all outbound connections from a specific server to external IPs, (2) determine if any of those IPs are known malicious, and (3) block the malicious IPs at the perimeter. The analyst has access to a SIEM, a threat intelligence platform, a firewall, and an EDR. Which sequence of tools should the analyst use to complete the playbook efficiently?
Select an answer first - 8
A playbook for a compromised endpoint requires the analyst to isolate the endpoint from the network, then collect a memory image for forensic analysis. The organization has an EDR, a SIEM, and a forensic imaging tool. The analyst needs to minimize the time the endpoint remains on the network. Which sequence of actions should the analyst take?
Select an answer first - 9
A security analyst is executing a playbook for a suspected phishing campaign. The playbook instructs the analyst to collect the email headers, extract the sender's IP address, and check whether that IP address has been observed in recent campaigns. Which tool should the analyst use to complete the IP address reputation check?
Select an answer first - 10
A playbook for a data loss prevention (DLP) incident requires the analyst to identify which user copied sensitive data to a USB drive, and then to block the user's ability to use USB devices. The organization has a DLP solution, an EDR, and an identity provider (IdP). Which tool should the analyst use to identify the user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.