Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 24

2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 3)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
30%of the exam

Questions 11–15

  1. 11foundation · medium

    A detection rule has been modified multiple times. The security team wants to understand what changes were made and when. What is the best practice to ensure this information is available?

    Select an answer first
  2. 12application · medium

    A detection rule that performs a regex match on the full HTTP request body is causing high CPU usage on the SIEM search head. The rule is important but does not need to run in real time. What is the best way to reduce the performance impact?

    Select an answer first
  3. 13foundation · medium

    A detection rule written in YAML for a SIEM platform fails to parse. The rule includes a field with a colon in the value, such as 'description: Alert: Suspicious activity'. What is the most likely syntax issue?

    Select an answer first
  4. 14application · medium

    A detection rule is designed to alert when a user account is locked out more than 5 times in 10 minutes. The rule uses the condition `event_type: 'user_lockout'` and a threshold of `count > 5` over a 10-minute window. During testing, the rule fires when exactly 5 lockout events occur. What is the most likely cause?

    Select an answer first
  5. 15application · medium

    A detection rule for 'new admin account creation' is not firing. The rule checks `event_type == 'user_create'` and `admin == true`. The analyst verifies that the SIEM receives the events and that a test event with both fields set to the expected values does not trigger the rule. What is the next logical troubleshooting step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.