Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 15

2.15 Recommend Tuning or Adapting Devices and Software Across Rules, Filters, and Policies 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    A network monitoring system has been generating alerts for a sudden increase in DNS traffic from a specific workstation. The baseline for that workstation shows that DNS traffic is typically low. The analyst investigates and finds that the workstation is running a legitimate backup application that uses DNS to resolve the backup server's hostname frequently. What should the analyst recommend?

    Select an answer first
  2. 17application · medium

    A security administrator is reviewing the firewall rule base and finds that a rule allowing legacy FTP traffic has not been used in six months. The company has migrated to SFTP for all file transfers. The administrator wants to maintain a clean rule base and reduce the attack surface. What should the administrator do?

    Select an answer first
  3. 18application · medium

    A university's network team observes that a new research collaboration tool generates large amounts of encrypted traffic to a specific cloud provider. The current web filter blocks all traffic to that provider's IP range, causing user complaints. Threat intelligence indicates that the provider's IP range is also used by a known malware family. The team wants to allow the legitimate tool while still blocking malicious activity. What should they do?

    Select an answer first
  4. 19foundation · easy

    Which scenario best illustrates adapting filters based on threat intelligence?

    Select an answer first
  5. 20application · medium

    A security analyst is tuning an intrusion detection system (IDS) that monitors a data center network. The analyst observes that a particular signature for 'ET TROJAN Win32/Agent Tesla Checkin' is firing on traffic from a legitimate internal server that performs web requests to a known-good external service. The signature is known to have a high false-positive rate in environments that use certain web proxies. What should the analyst do to reduce false positives while maintaining detection for other hosts?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.