
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 23
2.23 Evaluate Artifacts and Streams in a Packet Capture File 350-201 Practice Questions (Page 8)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
30%of the exam
Questions 36–40
- 36
When analyzing a capture, which artifact would you correlate with a TCP stream to confirm that a file was downloaded?
Select an answer first - 37
While examining a pcap, you see a packet with a TCP destination port of 443 and a TLS ClientHello message. Which field in the ClientHello would you inspect to determine the server name the client is trying to reach?
Select an answer first - 38
You are analyzing a pcap from a network breach. You see a TCP stream with an HTTP POST to a login page containing credentials, followed by a stream with a 302 redirect to a different domain, and then a stream with an HTTP GET to that domain with a session cookie. What is the most likely attack pattern?
Select an answer first - 39
An incident responder is analyzing a pcap file from a compromised host. The capture shows: (1) a TCP handshake to an external IP on port 445, (2) a series of SMB2 write requests, and (3) a subsequent HTTP POST to a different external IP. The responder needs to determine if the SMB traffic and the HTTP POST are related. Which approach is most effective?
Select an answer first - 40
In a pcap, you see a TCP packet with the URG flag set and a Urgent Pointer value of 0. What is the most likely interpretation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.