Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 18

2.18 Recommend Procedural and SOAR Workflows from the Described Issue Through Escalation and the Automation Needed for Resolution 350-201 Practice Questions (Page 5)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts
30%of the exam

Questions 21–25

  1. 21application · easy

    A SOAR platform is configured to run a playbook when a SIEM alert contains a specific indicator of compromise (IOC). The playbook automatically blocks the IOC on the firewall and sends a notification to the security team. Which element is the workflow trigger?

    Select an answer first
  2. 22application · medium

    A company's SOAR platform receives an alert for a user account that has attempted to authenticate 15 times in 5 minutes from an unusual geographic location. The playbook is designed to automatically disable the account and reset the password. However, the account belongs to a senior executive. What is the best approach?

    Select an answer first
  3. 23foundation · easy

    How does a SOAR platform typically integrate with a SIEM to enhance incident response?

    Select an answer first
  4. 24expert · hard

    A company's SOAR playbook automatically blocks IP addresses that are associated with a confirmed intrusion. However, the playbook has blocked a legitimate partner's IP address, causing a business outage. The team wants to prevent this from happening again. What is the best approach?

    Select an answer first
  5. 25expert · hard

    A company's incident response policy defines escalation criteria based on the number of affected users and the criticality of the affected system. The policy states that an incident must be escalated to the next tier if it affects more than 50 users OR if it involves a system classified as 'mission-critical'. A SOC analyst is handling an incident that affects 30 users on a system classified as 'business-essential' but not 'mission-critical'. The analyst has contained the incident and is confident it will not spread. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.