Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 4

3.4 Interpret the Sequence of Events During an Attack Based on Predictive AI Analysis of Traffic Patterns 350-201 Practice Questions (Page 2)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts
30%of the exam

Questions 6–10

  1. 6expert · hard

    A predictive AI model is trained to detect data exfiltration via HTTP. It flags a workstation that is sending large amounts of data to a cloud storage service. The AI's anomaly score is high because the workstation has never communicated with that service before. The security team investigates and finds that the user recently started using the service for a legitimate project. Which action should the team take to reduce future false positives?

    Select an answer first
  2. 7application · medium

    A predictive AI system reports the following alert sequence for a web application: (1) multiple failed logins from a single IP, (2) a successful login from the same IP, (3) a request to a URL with a SQL injection payload, (4) an outbound connection to an unknown IP. The analyst needs to reconstruct the attack timeline. Which stage does the successful login represent in this sequence?

    Select an answer first
  3. 8expert · hard

    A predictive AI system correlates the following events for a compromised host: (1) the host performs a port scan of the internal network, (2) the host exploits a vulnerability on a file server, (3) the host creates a new user account on the file server, (4) the host uses the new account to access sensitive documents. The security team must decide whether to prioritize containment of the host or the file server. Which consideration should drive the decision?

    Select an answer first
  4. 9application · medium

    A predictive AI tool identifies a sequence of events indicating a potential data exfiltration: (1) a user account is created on a domain controller, (2) the account is added to the Domain Admins group, (3) the account is used to access a file server and copy sensitive documents, (4) the data is uploaded to a cloud storage service. The incident response team needs to prioritize containment. Which action should be taken first?

    Select an answer first
  5. 10application · medium

    A predictive AI system reports the following sequence for a compromised server: (1) a new admin account is created, (2) the account is used to disable security monitoring, (3) the server begins sending encrypted data to an external IP. The analyst must interpret the sequence. Which stage does the creation of the new admin account represent?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.