Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 24

2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 6)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
30%of the exam

Questions 26–30

  1. 26expert · hard

    A detection rule for 'lateral movement via SMB' is not firing. The rule checks `event_type == 'smb_connection'` and `destination_port == 445`. The analyst confirms that SMB events are being ingested and that a test event with the correct values does not trigger the rule. Which troubleshooting step is most likely to reveal the issue?

    Select an answer first
  2. 27application · medium

    An analyst writes a detection rule to alert on suspicious PowerShell execution. The rule references the field `EventID` with value `4104` and `ScriptBlockText` containing `DownloadString`. Testing against a known malicious sample does not trigger the rule. The SIEM ingests Windows PowerShell operational logs, but the field is named `Script_Block_Text` in the normalized schema. What is the most likely cause?

    Select an answer first
  3. 28expert · hard

    A detection rule is written for a SIEM that ingests Windows Event Logs. The rule references the field `EventID` and the value `4625`. The rule does not fire, even though failed logins are occurring. The analyst discovers that the SIEM uses a custom parser that maps the raw event's `Event ID` field to `Event_Id` in the normalized schema. What is the most efficient way to fix the rule?

    Select an answer first
  4. 29expert · hard

    A SOC uses a version-controlled repository for detection rules. A recent change to a rule intended to reduce false positives also caused it to stop detecting a known attack. The team needs to revert the change but preserve the ability to reapply the tuning later. What is the best approach?

    Select an answer first
  5. 30application · medium

    A detection rule that correlates events across a 24-hour window is causing the SIEM to run out of memory during scheduled searches. The rule is critical and must remain in place. What is the best way to reduce the memory footprint?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.