
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 1
1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 7)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
20%of the exam
Questions 31–35
- 31
A security analyst is reviewing a playbook for handling a suspected ransomware infection. The playbook contains a step that checks whether the file hash of the suspicious executable matches a known-bad list. If the hash matches, the playbook directs the analyst to isolate the host; if not, it directs the analyst to continue monitoring. Which two components of the playbook are the analyst primarily interpreting in this step?
Select an answer first - 32
A security team is creating a playbook for a new type of phishing campaign. They want the playbook to start when a user clicks a link in an email that is later determined to be malicious. They also want the playbook to include a step that checks whether the user's device is a corporate-managed device before applying containment actions. Which two components should the team include in the playbook to meet these requirements?
Select an answer first - 33
A security team is reviewing a playbook for a data breach. The playbook has a trigger: 'Alert from DLP system for sensitive data exfiltration.' The first phase is 'Identification,' which includes the task 'Confirm whether the data includes PII.' The next phase is 'Containment,' which includes the action 'If PII is present, notify legal within 1 hour; otherwise, continue with standard containment.' The team has received a DLP alert and confirmed that the data includes PII. The team is also aware that the breach may involve data from EU residents, which could trigger GDPR notification requirements. What should the team do according to the playbook?
Select an answer first - 34
An incident responder is executing a playbook for a data exfiltration incident. The playbook includes a step that says: 'If the destination IP is in the approved external partners list, document the transfer and close the ticket; otherwise, escalate to the incident commander.' The responder finds the destination IP is NOT in the approved list. What is the responder's correct action according to the playbook?
Select an answer first - 35
A SOC analyst is reading a playbook for a DDoS attack on a web application. The playbook lists the following: 'If the traffic rate exceeds 10 Gbps, enable rate limiting on the edge firewall.' The analyst sees that the current traffic rate is 8 Gbps. What should the analyst do according to the playbook?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.