
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 4)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 16–20
- 16
A security analyst is investigating a suspected data breach. The pcap file shows an internal host making an HTTPS connection to an external IP on port 443, followed by a series of DNS TXT queries to a domain known for data exfiltration. The analyst needs to determine if the HTTPS connection and the DNS queries are related. Which approach is most effective?
Select an answer first - 17
An analyst is examining a pcap file and needs to find all packets that contain the string 'password' in the payload. Which Wireshark display filter should the analyst use?
Select an answer first - 18
An analyst is investigating a DNS exfiltration incident. The capture shows many DNS queries to an external domain, each with a subdomain that appears to be base64-encoded data. The analyst needs to reconstruct the exfiltrated data. What is the most effective approach?
Select an answer first - 19
You are analyzing a pcap from a compromised host. You find an HTTP POST to a known malicious domain with a filename 'update.exe' in the Content-Disposition header. You also see a subsequent TCP stream that contains binary data with a MZ header. What is the most likely scenario?
Select an answer first - 20
A network analyst is investigating a malware infection and has a pcap file. The analyst needs to reassemble the entire TCP conversation between the infected host and the command-and-control server to see the full payload. Which Wireshark feature should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.