
CiscoCertified Network Professional Cybersecurity (CBRCOR)
Domain 2Objective 24
2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 2)
Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
30%of the exam
Questions 6–10
- 6
A detection rule is written to alert when a process name is 'powershell.exe' AND the command line contains 'DownloadString'. The rule uses the condition: process_name == 'powershell.exe' AND command_line CONTAINS 'DownloadString'. However, the rule does not trigger for a known malicious event. Which change would most likely fix the rule?
Select an answer first - 7
A detection rule for 'data exfiltration via DNS' uses the field `dns_query_length` and checks if it is greater than 100. The rule does not fire on known tunneling traffic. The SIEM's DNS logs use `query_length` for the length field. The analyst also notices that the rule uses `dns_query_name` for the domain, but the log uses `query`. What is the most likely cause?
Select an answer first - 8
A detection rule triggers on any login failure event. The security team is overwhelmed by alerts from a single user who frequently mistypes their password. What is the most effective tuning adjustment to reduce false positives while still detecting brute-force attacks?
Select an answer first - 9
A rule alerts when a single user has more than 10 failed logins in 5 minutes. The SOC is seeing many alerts from a legacy application that retries authentication aggressively. The rule is meant to detect password spraying. Which tuning change best reduces false positives while preserving detection of password spraying?
Select an answer first - 10
A security team updates a detection rule to fix a false positive issue. After deploying the update, they notice that the rule no longer triggers on a known malicious pattern. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.