
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 3Objective 4
3.4 Interpret the Sequence of Events During an Attack Based on Predictive AI Analysis of Traffic Patterns 350-201 Practice Questions (Page 7)
Part of the Processes domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 2–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
30%of the exam
Questions 31–35
- 31
A predictive AI system flags a sequence of traffic patterns: a user authenticates from a new geolocation, then downloads a large file from an internal file server, then connects to a cloud storage provider. The AI assigns a high risk score. The analyst must decide whether this is a true attack or a false positive. Which additional context would most strongly support classifying this as a normal (non-malicious) pattern?
Select an answer first - 32
A security analyst reviews a predictive AI dashboard that flags a sequence of events: at 09:12, a single external IP performs a slow port scan; at 09:18, the same IP sends a crafted HTTP request to a web server; at 09:25, the web server initiates outbound connections to an IP known for C2. The AI labels this as a likely attack chain. The analyst needs to document the attack stages in order. Which sequence correctly maps the AI-flagged events to the attack stages?
Select an answer first - 33
A predictive AI system flags the following sequence for a finance department workstation: (1) the user receives a spear-phishing email with a malicious attachment, (2) the attachment exploits a zero-day vulnerability in the PDF reader, (3) the workstation establishes a connection to an external IP on port 443, (4) the workstation then begins accessing internal file shares and compressing files, (5) the compressed files are uploaded to a cloud storage service. The security team has limited resources and must decide the most effective single action to stop the attack. Which action should be taken?
Select an answer first - 34
A network team deploys a predictive AI tool that analyzes traffic patterns to detect attack sequences. The tool flags a series of small, periodic data transfers from a workstation to an external IP during off-hours. The analyst must determine if this is malicious. Which characteristic of the pattern would most likely cause the predictive AI to flag it as a potential attack sequence?
Select an answer first - 35
A predictive AI system reports the following sequence for a web application: (1) an attacker probes the application for SQL injection vulnerabilities, (2) a successful SQL injection is detected, (3) the attacker extracts database credentials, (4) the credentials are used to access a backend database. The security team must decide the most critical point to interrupt the attack. Which action would be most effective at breaking the attack chain?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.