Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 24

2.24 Troubleshoot Existing Detection Rules 350-201 Practice Questions (Page 7)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
30%of the exam

Questions 31–33

  1. 31application · medium

    A detection rule that correlates login failures across multiple accounts using a 24-hour sliding window is causing significant CPU load on the SIEM. The rule is important but does not need to run in real time. Which change best reduces performance impact while maintaining detection capability?

    Select an answer first
  2. 32application · medium

    A security analyst has written a new detection rule for a SIEM. Before deploying it to production, the analyst wants to validate that the rule triggers correctly on known malicious activity and does not trigger on normal traffic. What is the best approach?

    Select an answer first
  3. 33foundation · medium

    A detection rule is generating too many false positives. The analyst has already reviewed the rule logic and confirmed it is correct. What is the next best step to troubleshoot the issue?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 350-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.