
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 15
2.15 Recommend Tuning or Adapting Devices and Software Across Rules, Filters, and Policies 350-201 Practice Questions (Page 6)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
30%of the exam
Questions 26–30
- 26
What is the primary driver for adjusting security policies in an organization?
Select an answer first - 27
A large enterprise has an intrusion prevention system (IPS) deployed inline. The security team is receiving a high volume of false-positive alerts for a signature that detects 'ET POLICY Outbound HTTP with Basic Auth'. The traffic is generated by a legacy application that uses HTTP basic authentication to a known internal server. The application is scheduled to be replaced in 18 months. The security team wants to reduce the alert noise without losing visibility into other potential basic-auth abuse. The compliance team also requires that any rule changes be documented and reviewed. What should the security team do?
Select an answer first - 28
A security analyst notices that the intrusion prevention system (IPS) has been generating a high volume of alerts for a signature that detects SQL injection attempts. After reviewing the traffic, the analyst determines that the alerts are triggered by a legacy application that sends database queries in the URL parameters. The application is scheduled to be decommissioned in six months. What should the analyst recommend to reduce the alert noise while maintaining visibility into real SQL injection attempts?
Select an answer first - 29
After a phishing incident, a security team reviews the email security gateway logs and finds that the existing rule for blocking executable attachments was bypassed because the attacker used a double extension (e.g., 'invoice.pdf.exe'). The team wants to update the rules to prevent similar attacks. What should they do?
Select an answer first - 30
A network administrator needs to modify a content filter to allow a new business-critical web application that was recently deployed. Which action best represents adapting filters?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 350-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.