Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 4

2.4 Evaluate the Security Controls of an Environment, Diagnose Gaps, and Recommend Improvement 350-201 Practice Questions (Page 6)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
3concepts
30%of the exam

Questions 26–30

  1. 26expert · hard

    A security team is evaluating the organization's backup and recovery controls. They find that backups are performed daily, but the recovery time objective (RTO) is 4 hours, and the actual recovery time is 12 hours. The team must recommend improvements. Which recommendation best addresses the gap?

    Select an answer first
  2. 27application · medium

    A security team is evaluating the effectiveness of their access control system. They find that user accounts are not being disabled promptly when employees leave the company. The security policy requires that accounts be disabled within 24 hours of termination. What is the most appropriate recommendation?

    Select an answer first
  3. 28foundation · easy

    A security team compares the current security posture of their organization to the CIS Controls baseline. What is this process called?

    Select an answer first
  4. 29application · medium

    A company has implemented a SIEM solution, but the security team discovers that the SIEM is not receiving logs from the company's cloud-based email service. The security policy requires that email logs be included in the SIEM. What should the team do?

    Select an answer first
  5. 30expert · medium

    An organization has deployed a SIEM and is ingesting logs from firewalls, servers, and endpoints. The security team notices that the SIEM is not correlating events from the firewall and the endpoint because the firewall logs are in a different time zone than the endpoint logs. What is the most effective way to improve the SIEM's effectiveness?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.