Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 3Objective 4

3.4 Interpret the Sequence of Events During an Attack Based on Predictive AI Analysis of Traffic Patterns 350-201 Practice Questions (Page 5)

Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts
30%of the exam

Questions 21–25

  1. 21expert · hard

    A predictive AI tool identifies a sequence of events indicating a ransomware attack: (1) a user opens a malicious attachment, (2) a PowerShell script downloads a ransomware binary, (3) the binary encrypts files on the local machine and network shares, (4) the machine displays a ransom note. The security team has a backup solution that can restore encrypted files, but the restore process takes 4 hours. Which action should be prioritized to minimize the impact?

    Select an answer first
  2. 22expert · hard

    A predictive AI system flags a sequence of events for a user: (1) the user logs in from a new IP address, (2) the user accesses a file share, (3) the user transfers a file to an external cloud service. The AI assigns a high risk score. The user is a known remote worker who frequently travels. However, the file share contains sensitive project data, and the cloud service is a personal Dropbox account. The analyst must decide whether to escalate this as a potential data exfiltration. Which combination of factors most strongly supports escalation?

    Select an answer first
  3. 23foundation · easy

    Which incident response action is most directly supported by predictive AI insights indicating that a host is likely to be used for lateral movement next?

    Select an answer first
  4. 24expert · hard

    A security operations center (SOC) uses a predictive AI tool that flags attack sequences. The tool reports the following for a compromised workstation: (1) a user opens a phishing attachment, (2) a PowerShell script downloads a payload, (3) the payload creates a scheduled task, (4) the workstation begins scanning the internal network. The SOC has a policy to contain threats immediately, but the workstation is used by a remote employee who is currently on a critical video call. The analyst must balance containment with business continuity. Which action best balances the need to stop the attack with the need to maintain the employee's productivity?

    Select an answer first
  5. 25expert · hard

    A predictive AI system reports the following alert sequence for a server: (1) a brute-force attack on SSH, (2) a successful SSH login, (3) a privilege escalation command, (4) a connection to an external IP on port 4444. The incident response team has a playbook that says to block the attacking IP first. However, the AI indicates the attack is already at the command and control stage. Which action is the most effective next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.