Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 1Objective 1

1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 6)

Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts
20%of the exam

Questions 26–30

  1. 26application · medium

    A playbook for a compromised account includes the following instruction: 'If the account is a service account, coordinate with the application owner before disabling it; otherwise, disable the account immediately.' The analyst discovers the compromised account is a service account. What is the correct interpretation of this playbook step?

    Select an answer first
  2. 27application · medium

    A junior analyst is reviewing a playbook for a malware outbreak. The playbook is organized into sections: 'Preparation', 'Detection and Analysis', 'Containment, Eradication, and Recovery', and 'Post-Incident Activity'. Within the 'Containment, Eradication, and Recovery' section, there is a step that says: 'If the infected host is a domain controller, coordinate with the identity team before isolating.' What is the purpose of this step in the playbook structure?

    Select an answer first
  3. 28application · easy

    A security analyst is reviewing a playbook for a phishing campaign. The playbook includes a section that describes the desired end state: 'All malicious emails are quarantined, the sender is blocked, and the user is notified.' The analyst is trying to understand what this section represents. Which playbook component is this?

    Select an answer first
  4. 29application · medium

    A playbook for a DDoS incident includes the following step: 'If the attack traffic originates from a single source IP, apply a blackhole route; otherwise, engage the upstream provider for rate limiting.' The analyst sees that the attack is coming from a distributed botnet with many source IPs. What should the analyst do according to the playbook?

    Select an answer first
  5. 30application · medium

    A SOC analyst is following a playbook for a network intrusion. The playbook has the following steps: 1) Collect packet captures. 2) Analyze the traffic for indicators of compromise. 3) If indicators are found, block the source IP. 4) If no indicators are found, close the ticket. 5) Document findings. The analyst has completed step 2 and found indicators of compromise. What should the analyst do next?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.