Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 1

1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 4)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts
20%of the exam

Questions 16–20

  1. 16expert · hard

    A playbook for a data breach includes the following steps: 1) Identify the data type involved, 2) If the data is regulated, notify legal; if not, proceed to step 3, 3) Contain the affected systems, 4) Notify the data owner. The analyst discovers that the data is regulated and also that the data owner is on vacation. What is the correct sequence of actions according to the playbook?

    Select an answer first
  2. 17foundation · easy

    In a playbook, the 'expected outcome' of a containment step is 'the compromised host is isolated from the network.' What does this component tell the analyst?

    Select an answer first
  3. 18foundation · easy

    Given the following playbook excerpt: Step 1: Check if the alert severity is 'high'. Step 2: If yes, escalate to the SOC manager. Step 3: If no, investigate the alert. What is the correct interpretation of this workflow?

    Select an answer first
  4. 19application · medium

    A playbook for a web application attack includes these steps: 1) Review the web server logs for the attack pattern, 2) If the attack pattern matches a known exploit, block the source IP; if not, capture the logs for further analysis, 3) Report the incident to the security manager. The analyst reviews the logs and finds the attack pattern does NOT match a known exploit. What should the analyst do next?

    Select an answer first
  5. 20application · medium

    A playbook for a ransomware incident includes the following: 'When a ransomware alert is received, the analyst should isolate the affected host, then check if the host is a domain controller. If it is a domain controller, the analyst should coordinate with the identity team before proceeding.' Which component is the 'check if the host is a domain controller' step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.