
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 1
1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 3)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
20%of the exam
Questions 11–15
- 11
A security team is designing a playbook for a new incident type. They want the playbook to guide analysts through the following flow: first, identify the affected systems; then, if the systems are critical, apply immediate containment; otherwise, perform a deeper investigation; finally, document the incident. Which playbook structure best represents this flow?
Select an answer first - 12
A security team is creating a playbook for a data breach involving customer records. They want the playbook to clearly show the sequence of steps, including where a decision must be made about whether the breach involves personally identifiable information (PII). Which playbook structure best supports this requirement?
Select an answer first - 13
Which playbook component describes the desired result that should be achieved after a particular action is completed?
Select an answer first - 14
A security analyst is reviewing a playbook for handling a suspected ransomware infection. The playbook begins with a section that lists specific indicators such as unusual file extensions and ransom notes, followed by a decision point that asks whether the affected host is a domain controller. If the answer is yes, the playbook directs the analyst to isolate the host and escalate to the incident commander. If no, it directs the analyst to continue with containment. Which component of the playbook is the analyst most directly interpreting when determining which branch to follow?
Select an answer first - 15
A playbook for a phishing incident has these steps in order: 1) Validate the email headers, 2) Determine if the user clicked the link, 3) If clicked, quarantine the user's machine, 4) If not clicked, delete the email. What should the analyst do if the user clicked the link?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.