Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 24

2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 1)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst notices that a detection rule for 'successful brute-force login' never fires, even though the SOC has confirmed multiple successful logins after repeated failures. The rule uses the condition: `(failures > 5) and (success == true)`. The event schema logs failed and successful logins as separate event types. What is the most likely reason the rule does not trigger?

    Select an answer first
  2. 2application · medium

    A SOC analyst modifies a detection rule to add a new field condition. After deploying the change, the rule stops generating alerts that previously fired. The team needs to understand what changed. Which action is most appropriate?

    Select an answer first
  3. 3foundation · medium

    A detection rule is not triggering as expected. The analyst has verified that the rule syntax is correct and the fields are mapped correctly. What is the next logical step in the troubleshooting methodology?

    Select an answer first
  4. 4foundation · medium

    A detection rule performs a lookup against a large external threat intelligence feed for every event. The rule is causing delays in alert generation. What is the most effective way to reduce the performance impact?

    Select an answer first
  5. 5application · medium

    A junior analyst writes a detection rule with the following condition: `(source_ip == '10.0.0.0/8' and action == 'allow') or (destination_port == 443)`. The rule is intended to alert on allowed traffic from the internal 10.0.0.0/8 network to any destination. The rule triggers on traffic from external IPs to port 443, which is not intended. What is the flaw in the rule?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.