350-201 Performing Cybersecurity Using Cisco Security Technologies (CBRCOR) Practice Questions
Prepare for 350-201 with more than an answer.
- Exam fee
- $400 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 4
- Cybersecurity Fundamentals20%
- Techniques30%
- Processes30%
- Automation20%
- 1
What is the primary purpose of the
recoveryphase in the NIST incident response lifecycle?Show answer details
Correct answer: D
The recovery phase focuses on restoring systems to normal business operations after the threat has been eradicated. This includes activities like restoring systems from clean backups, rebuilding compromised systems, and validating that they are fully operational and secure before returning them to production.
- 2
A SOC uses a playbook for ransomware incidents. Part of the playbook involves automatically isolating an infected endpoint using Cisco Secure Endpoint, enriching file hashes with Cisco Threat Grid, and creating a ticket in the incident management system. Which security concept does this automated, multi-tool workflow exemplify?
Show answer details
Correct answer: A
This workflow is a prime example of SOAR. It involves Orchestration (coordinating actions across multiple disparate tools like Secure Endpoint, Threat Grid, and a ticketing system), Automation (executing these actions without human intervention), and Response (taking steps to contain and analyze the threat).
- 3
A forensics analyst is examining a full packet capture (PCAP) file from a client machine suspected of communicating with a command-and-control server. The analyst applies a Wireshark filter
tcp.flags.syn == 1 and tcp.flags.ack == 1. What is the purpose of this filter?Show answer details
Correct answer: C
This filter looks for TCP packets where both the SYN (synchronize) and ACK (acknowledgment) flags are set. In the TCP three-way handshake, this SYN/ACK packet is the second step, sent by the server in response to the client's initial SYN packet. It indicates that the server has an open port and is acknowledging the connection request. This helps an analyst quickly identify successful outbound connection attempts.
- 4
A healthcare organization must protect patient data in compliance with HIPAA. An analyst is tasked with implementing controls to prevent the unauthorized exfiltration of electronic protected health information (ePHI) via email and cloud storage services. Which security technology is specifically designed to address this requirement?
Show answer details
Correct answer: B
Data Loss Prevention (DLP) solutions are designed to address this exact use case. They use deep content inspection and contextual analysis to identify and classify sensitive data like ePHI. Based on configured policies, a DLP system can then monitor, alert on, or block attempts to send this data outside the organization's control, such as through email or uploads to cloud services.
- 5
A Python script is used to query an API that returns data in JSON format. The raw response is stored in a variable named
api_response. The JSON structure is{"data": {"ip_address": "192.0.2.1", "status": "malicious"}}. Which line of Python code correctly extracts the value 'malicious' from the response, assuming thejsonlibrary has been imported and the response text has been loaded into a dictionary calledresponse_dict?Show answer details
Correct answer: C
When JSON data is loaded into a Python dictionary, nested objects are accessed using square bracket key notation. To get the 'status' value, you must first access the 'data' key, which returns another dictionary, and then access the 'status' key within that nested dictionary.
- 6
A security operations team needs to improve its ability to detect lateral movement within their network, including traffic between servers in the same datacenter VLAN (East-West traffic). The existing security stack relies on a perimeter firewall and endpoint protection. Which technology should be implemented to gain visibility into this internal traffic and identify anomalous behavior?
Show answer details
Correct answer: B
A network traffic analysis solution, such as Cisco Secure Network Analytics, uses flow data (like NetFlow) from network devices to gain deep visibility into all traffic, including East-West traffic. It can then apply behavioral analytics to baseline normal communication patterns and detect anomalies indicative of lateral movement, such as a server scanning other internal hosts.
- 7
A SOC analyst is reviewing the following simplified Cisco SecureX orchestration workflow. What is the primary function of this workflow?
sequenceDiagram participant EDR as Cisco Secure Endpoint participant SOAR as SecureX Orchestration participant Sandbox as Cisco Threat Grid participant SIEM EDR->>SOAR: New File Detected (Low Prevalence) SOAR->>Sandbox: Submit File Hash for Analysis Sandbox-->>SOAR: Return Threat Score alt Threat Score > 90 SOAR->>EDR: Isolate Endpoint SOAR->>SIEM: Create High-Priority Incident else Threat Score <= 90 SOAR->>SIEM: Create Low-Priority Informational Event endShow answer details
Correct answer: C
The workflow diagram clearly shows an automated process for handling suspicious files. It starts with detection on an endpoint (EDR), proceeds to automated analysis (Sandbox), and then takes a conditional response action (Isolate Endpoint and create incident) based on the analysis result. This entire sequence automates the initial triage and response steps that a SOC analyst would typically perform manually.
- 8
A SOC analyst is reviewing NetFlow data from Cisco Secure Network Analytics (formerly Stealthwatch) and observes a sustained, low-volume stream of outbound traffic on TCP port 53 from a database server. This server is not authorized to perform DNS resolution for external domains. The traffic pattern avoids high-volume thresholds that would trigger standard alerts. Which analytic technique is most effective for identifying this potential DNS tunneling activity?
Show answer details
Correct answer: B
Behavioral anomaly detection is the most effective technique in this scenario. It establishes a baseline of normal activity for the database server and flags the new, unauthorized DNS traffic as a deviation, even if it is low-volume. Statistical volume analysis would likely miss this low-and-slow traffic. Signature-based detection is ineffective as DNS tunneling does not have a universal signature. Heuristic analysis of payloads is not possible with NetFlow, which primarily contains metadata.
- 9
A DevSecOps engineer is building a Python script to automate the enrichment of IP address indicators using the Cisco SecureX API. The script must check if an IP address has a malicious disposition and, if so, create a new sighting associated with a specific incident. Which two API endpoints are essential for this workflow? (Select TWO).
Show answer details
Correct answer: B, D
The
/deliberate/observablesendpoint is used to get dispositions (judgements) for observables like IP addresses from various threat intelligence sources integrated with SecureX. This step is necessary to determine if the IP is malicious.The
/enrich/observe/observablesendpoint is used to submit observables to SecureX. This action creates sightings, which link the observable (the malicious IP) to its source and context, effectively recording its presence in the environment for incident response and tracking. - 10
During a malware analysis process in a sandbox environment, a file is observed performing the following sequence of actions:
- Executes
vssadmin.exe Delete Shadows /All /Quiet. - Makes numerous file modifications with high entropy in user directories.
- Establishes an outbound connection to a known Tor exit node.
- Deletes itself from the original execution path.
Which type of malware is most likely being analyzed?
Show answer details
Correct answer: C
This sequence of actions is a classic signature of ransomware. Deleting volume shadow copies (
vssadmin) prevents easy restoration of files. Modifying files with high entropy indicates encryption. C2 communication over Tor is common for anonymity, and self-deletion is a standard anti-forensics technique. - Executes
