Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 24

2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 4)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
30%of the exam

Questions 16–20

  1. 16application · medium

    A SIEM is experiencing high CPU usage because of a rule that performs a complex join across multiple event types over a 7-day window. The rule is critical but does not need to alert in real time. Which change best reduces performance impact while preserving the rule's detection capability?

    Select an answer first
  2. 17foundation · medium

    A detection rule in a SIEM references the field 'source_ip' to identify the source address of a network connection. However, the event schema for the network logs uses 'src_ip' instead. What is the most likely result of this field mismatch?

    Select an answer first
  3. 18foundation · medium

    A detection rule is intended to trigger when a user logs in from an IP address outside the corporate network AND the login occurs outside business hours. The rule currently uses the condition: (src_ip NOT IN corporate_networks) OR (hour NOT BETWEEN 9 AND 17). Why does the rule trigger more often than expected?

    Select an answer first
  4. 19application · medium

    A detection rule in a SIEM is written to alert on suspicious PowerShell activity. The rule references the field `EventID` with a value of `4104`. The rule never fires, even though PowerShell script block logging is enabled and events are being collected. What is the most likely issue?

    Select an answer first
  5. 20expert · hard

    A detection rule alerts when a single user downloads more than 500 MB in 1 hour. The rule is generating false positives for a backup application that legitimately transfers large amounts of data. The security team wants to reduce false positives without missing data exfiltration. The backup application uses a dedicated service account. What is the best adjustment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.