
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 15
2.15 Recommend Tuning or Adapting Devices and Software Across Rules, Filters, and Policies 350-201 Practice Questions (Page 2)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
30%of the exam
Questions 6–10
- 6
A hospital's security team is reviewing the firewall policy after a ransomware outbreak that spread via SMBv1. The current policy allows SMBv1 traffic between internal segments for legacy medical devices. The team wants to reduce the risk of lateral movement while maintaining the functionality of those devices. What should they do?
Select an answer first - 7
A company's web application firewall (WAF) is blocking a new API endpoint that uses JSON payloads with special characters. The WAF's default rule set flags these payloads as SQL injection attempts. The API is legitimate and used by a partner integration. The company wants to allow the API traffic while still protecting against SQL injection. What should they do?
Select an answer first - 8
After a security incident, a team identifies that a specific rule failed to detect the attack. What is the best way to incorporate this feedback into rule modifications?
Select an answer first - 9
A financial services company has historically allowed employees to access personal webmail from corporate devices. After a recent phishing incident that originated from a personal webmail account, the risk committee has decided to prohibit personal webmail access during business hours. The security team must implement this change with minimal disruption to business operations. What should the security team do?
Select an answer first - 10
A company's email security gateway is blocking emails that contain a specific attachment file type, such as .exe, to prevent malware delivery. The human resources department regularly sends out a legitimate .exe installer for a new employee onboarding tool. The security team has verified that the installer is digitally signed and hashes match the official source. What should the security team do to allow this legitimate attachment while maintaining protection against malicious executables?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.