Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 1

1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 2)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts
20%of the exam

Questions 6–10

  1. 6application · medium

    A SOC analyst is following a playbook for a phishing email reported by a user. The playbook lists these steps in order: 1) Verify the email headers, 2) Check if the URL is on the blocklist, 3) If the URL is blocklisted, block the sender; if not, submit the URL for analysis, 4) Notify the user. The analyst has verified the headers and found the URL is not on the blocklist. According to the playbook, what should the analyst do next?

    Select an answer first
  2. 7foundation · easy

    A playbook contains a step that says: 'If the file hash matches a known-bad hash, block the hash on the firewall.' What is the purpose of the 'if' clause in this step?

    Select an answer first
  3. 8foundation · easy

    In a typical security playbook, which section is most likely to appear immediately after the initial trigger or alert is received?

    Select an answer first
  4. 9application · easy

    An incident responder is executing a playbook for a suspected insider threat. The playbook includes a step that says: 'If the user's access level is administrative, disable the account immediately; otherwise, monitor the account for 24 hours.' The responder has determined that the user has standard user access. What action should the responder take?

    Select an answer first
  5. 10expert · hard

    An incident responder is executing a playbook for a worm outbreak. The playbook has the following steps: 1) Identify the patient-zero host. 2) If the host is a server, isolate it and notify the server team. 3) If the host is a workstation, isolate it and notify the user's manager. 4) After either action, scan the entire network for other infected hosts. The responder has identified that the patient-zero host is a server. The responder is also aware that the server hosts a critical application that cannot be offline for more than 30 minutes. The playbook does not specify a time limit for isolation. What should the responder do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.