Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 1

1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 1)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts
20%of the exam

Questions 1–5

  1. 1expert · hard

    A SOC is executing a playbook for a malware outbreak. The playbook has a step that says: 'If the infected host is a domain controller, coordinate with the identity team before isolating; otherwise, isolate immediately.' The analyst receives a malware alert for a host that is a domain controller. However, the identity team is currently unavailable due to an ongoing outage. The analyst must decide how to proceed while following the playbook's intent. What should the analyst do?

    Select an answer first
  2. 2expert · hard

    An incident responder is executing a playbook for a suspected data exfiltration. The playbook has the following steps: 1) Identify the source of the exfiltration. 2) If the source is an internal user, disable the user's account. 3) If the source is an external attacker, block the attacker's IP. 4) After either action, notify the security manager. The responder has identified that the source is an internal user who is also a senior executive. The responder is concerned that disabling the account will cause reputational damage. What should the responder do?

    Select an answer first
  3. 3expert · hard

    A security team is reviewing a playbook for a ransomware incident. The playbook has a trigger: 'Ransom note discovered on a workstation.' The first phase is 'Containment,' which includes the task 'Isolate the workstation.' The next phase is 'Eradication,' which includes the action 'Remove the malware and restore from backup.' The team has discovered a ransom note on a workstation that is also used for administrative tasks. The team is concerned that isolating the workstation will prevent the administrator from performing critical tasks. What should the team do?

    Select an answer first
  4. 4expert · medium

    A security analyst is executing a playbook for a DDoS attack. The playbook has the following steps: 1) Verify the attack by checking traffic volume. 2) If traffic volume exceeds 20 Gbps, enable rate limiting. 3) If traffic volume is between 10 and 20 Gbps, monitor for 30 minutes. 4) If traffic volume is below 10 Gbps, close the ticket. 5) After any action, notify the network team. The analyst observes that the traffic volume is 15 Gbps. What should the analyst do?

    Select an answer first
  5. 5application · easy

    A junior analyst is reviewing a playbook for a malware outbreak. The playbook includes a section titled 'Triggers' that lists 'Endpoint detection alert for Trojan.GenericKD' and 'User report of slow computer with pop-ups.' The analyst is trying to determine whether a specific alert should initiate the playbook. Which statement best describes the role of the trigger in this context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.