
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 4
2.4 Evaluate the Security Controls of an Environment, Diagnose Gaps, and Recommend Improvement 350-201 Practice Questions (Page 4)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
3concepts
30%of the exam
Questions 16–20
- 16
A company's security policy requires multi-factor authentication (MFA) for all remote access. A review finds that the VPN is configured to accept only username and password. Which control gap is present?
Select an answer first - 17
An organization's endpoint protection platform (EPP) is configured to quarantine files detected as malware. During a review, the security team notices that the EPP is not receiving signature updates because the update server is unreachable from the endpoint network. What is the most likely impact on the security control's effectiveness?
Select an answer first - 18
An organization has a security policy that requires all administrative access to be protected by multi-factor authentication (MFA). The current environment uses MFA for VPN access but not for direct console access to servers. The security team has limited budget and must decide whether to implement MFA for console access or to implement a privileged access management (PAM) solution that includes MFA. What is the most appropriate recommendation?
Select an answer first - 19
A gap analysis reveals that the organization lacks multi-factor authentication (MFA) for remote VPN access, and also lacks a formal incident response plan. The VPN is used by all employees, and the incident response plan is only needed during a breach. Which improvement should be prioritized first?
Select an answer first - 20
A company has implemented a security information and event management (SIEM) system, but the security team is overwhelmed by the volume of alerts, many of which are false positives. The team is considering tuning the SIEM to reduce noise, but they are concerned about missing real threats. The security policy requires that all security events be monitored. What is the most appropriate recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.