
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 1Objective 1
1.1 Interpret the Components Within a Playbook 350-201 Practice Questions (Page 8)
Part of the Fundamentals domain, which accounts for 20% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
20%of the exam
Questions 36–37
- 36
An incident responder is executing a playbook for a phishing email reported by an employee. The playbook has the following steps: 1) Verify the email header and URL reputation. 2) If the URL is malicious, block the sender and quarantine the email. 3) If the URL is not malicious, close the ticket. 4) After either action, notify the user. The responder has just verified that the URL is malicious. According to the playbook, what should the responder do next?
Select an answer first - 37
A SOC manager is reviewing a playbook for a phishing incident. The playbook has a trigger: 'User reports a suspicious email.' The first phase is 'Triage,' which includes the task 'Determine if the email contains a malicious attachment.' The next phase is 'Containment,' which includes the action 'If the attachment is malicious, quarantine the email and block the sender; otherwise, close the ticket.' The manager notices that the playbook does not include a step to notify the user of the outcome. The manager wants to add a notification step. Where should the notification step be placed to align with the playbook's flow?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.