Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 4

3.4 Interpret the Sequence of Events During an Attack Based on Predictive AI Analysis of Traffic Patterns 350-201 Practice Questions (Page 1)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A predictive AI model is designed to detect DNS tunneling. It flags a client that is making a high volume of DNS queries to a single domain, with each query containing a long random subdomain. The AI also notes that the client is sending data to a known malicious IP via DNS responses. Which interpretation of this sequence is most accurate?

    Select an answer first
  2. 2foundation · easy

    When interpreting an attack sequence from predictive AI outputs, what does the chronological order of events primarily reveal?

    Select an answer first
  3. 3application · medium

    A predictive AI model is trained on network flow data to detect early signs of ransomware. It flags a workstation that suddenly starts encrypting files on a network share and simultaneously communicates with an IP that has a low reputation. The AI also notes that the workstation's user typically logs in at 9 AM, but the activity occurs at 3 AM. Which combination of factors most strongly indicates a malicious attack sequence rather than a false positive?

    Select an answer first
  4. 4foundation · easy

    Which attack stage is most directly associated with an AI alert that flags unusual outbound traffic to a known command-and-control server?

    Select an answer first
  5. 5foundation · easy

    What is the primary basis for predictive AI to distinguish normal traffic from malicious patterns?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.