
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 4
2.4 Evaluate the Security Controls of an Environment, Diagnose Gaps, and Recommend Improvement 350-201 Practice Questions (Page 1)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
3concepts
30%of the exam
Questions 1–5
- 1
A company's security team is reviewing their network segmentation controls. They find that the firewall rule set allows any host in the DMZ to initiate connections to any host in the internal database subnet on TCP 1433. The stated security policy requires that only the application server subnet can reach the database subnet. Which action best addresses the identified gap?
Select an answer first - 2
A security team is comparing their organization's access control policy to the principle of least privilege. They find that many users have domain administrator rights that are not required for their job functions. What is the most appropriate recommendation to close this gap?
Select an answer first - 3
During a security control evaluation, a security analyst reviews the configuration of a firewall and compares it against the organization's security policy. Which activity is the analyst performing?
Select an answer first - 4
A company is assessing its security posture against the NIST Cybersecurity Framework. The assessment shows that the company has strong detection controls but weak response capabilities. Which recommendation best addresses the identified gap?
Select an answer first - 5
An organization is required to comply with PCI DSS, which mandates that cardholder data be encrypted. The organization currently encrypts data in transit but not data at rest. The security team is evaluating whether to implement full-disk encryption on all servers or to encrypt only the databases that store cardholder data. The organization has limited budget and the servers are used for multiple purposes. What is the most appropriate recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.