CISCO · 350-201

Cisco 350-201 CBRCOR Exam Practice Questions

228 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 228 questions in this pack

Question 1

Refer to the exhibit. A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?

Exhibit for question 1

  1. Limit the number of API calls that a single client is allowed to make
  2. Add restrictions on the edge router on how often a single client can access the API
  3. Reduce the amount of data that can be fetched from the total pool of active clients that call the API
  4. Increase the application cache of the total pool of active clients that call the API
Show answer and explanation

Correct answer: A. Limit the number of API calls that a single client is allowed to make

allowed to make The exhibit shows one threat actor flooding a cloud application with concurrent API requests until legitimate users are denied access, which is a single source denial of service condition. The countermeasure is API rate limiting, which caps how many calls any one client may issue in a given time window. Enforcing per-client quotas at the API layer keeps one caller from consuming all capacity and preserves equitable access for the rest of the user community.

Why the other options are wrong

  • B. Edge router restrictions act on network flows without visibility into API calls or client identity, so they cannot enforce fair per-client request quotas for the application.
  • C. Shrinking the amount of data returned to all active clients degrades service for legitimate users while leaving the flood of concurrent requests untouched.
  • D. Adding application cache speeds up data retrieval but does nothing to limit request volume from an abusive client.

Question 2

A threat actor attacked an organization's Active Directory server from a remote location, and in a thirty-minute timeframe, stole the password for the administrator account and attempted to access 3 company servers. The threat actor successfully accessed the first server that contained sales data, but no files were downloaded. A second server was also accessed that contained marketing information and 11 files were downloaded. When the threat actor accessed the third server that contained corporate financial data, the session was disconnected, and the administrator's account was disabled. Which activity triggered the behavior analytics tool?

  1. accessing the Active Directory server
  2. accessing the server with financial data
  3. accessing multiple servers
  4. downloading more than 10 files
Show answer and explanation

Correct answer: C. accessing multiple servers

Behavior analytics compares activity against a learned baseline for the account, and a single administrator account reaching three different servers from a remote location inside thirty minutes is the anomaly that stands out. That pattern matches lateral movement following credential theft, which is exactly what user and entity behavior analytics is tuned to detect. The response confirms it: the session was killed and the account disabled at the third server, not at the point of the file downloads.

Why the other options are wrong

  • A. Administrative access to the Active Directory server is normal activity for that account and matches the existing baseline on its own.
  • B. The financial server was simply where the session was terminated, and touching one server does not constitute the anomalous pattern being scored.
  • D. Eleven file downloads within an authorized session is a lesser signal, and the tool did not act at that point since the session continued to a third server.

Question 3

Refer to the exhibit. A security analyst needs to investigate a security incident involving several suspicious connections with a possible attacker. Which tool should the analyst use to identify the source IP of the offender?

Exhibit for question 3

  1. packet sniffer
  2. malware analysis
  3. SIEM
  4. firewall manager
Show answer and explanation

Correct answer: A. packet sniffer

The exhibit is a host connection table that lists the local host, remote host names and ports, and connection states, but it does not expose the actual packet contents or resolve the true remote addresses behind those sessions. A packet sniffer captures the live traffic for those sessions so the analyst can read the IP headers and pin down the offender's source IP. Packet level capture is the tool that turns an ambiguous connection listing into confirmed attacker addressing.

Why the other options are wrong

  • B. Malware analysis examines binaries and their behavior, which does not yield the network addressing of the remote peer in these sessions.
  • C. A SIEM reports on logs that have already been collected and normalized, so it cannot supply the packet level addressing detail this host based connection list is missing.
  • D. A firewall manager administers rules and policy objects rather than capturing and inspecting the traffic needed to attribute a source IP.

See all 10 free questions Get the full pack, US$39

228 practice questions for Cisco 350-201 CBRCOR v1.2, the core exam for CCNP Cybersecurity, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 228 questions across all four CBRCOR domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed 350-201 attempt costs another US$400. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 228 questions

What makes the CBRCOR hard

CBRCOR is the professional-level SOC exam, and since January 2025 it sits under a new name: the CyberOps Professional track became CCNP Cybersecurity and the exam moved to v1.2. The domains and weights did not move, but the v1.2 topics added AI to monitoring and analysis, so an older bank misses those items.

Techniques and Processes are 30% each. Techniques covers AI-powered data analytics, hardening machine images, DevSecOps, threat intelligence platforms, DLP, SIEM data management, and SOAR workflows. Processes is the investigative side: threat models, the full malware analysis sequence, predictive AI analysis of traffic patterns, endpoint intrusion, IOCs and IOAs, and CVSS triage. Fundamentals covers playbooks, compliance frameworks and cloud security operations. Automation expects you to read and modify Python, work with JSON, CSV and XML, use Bash, and describe CI/CD and infrastructure as code.

About the exam

350-201 (Performing Cybersecurity Using Cisco Security Technologies v1.2, CBRCOR) earns the Cisco Certified Specialist, Cybersecurity Core certification and is the core exam for CCNP Cybersecurity. It covers security operations fundamentals, hardening and detection techniques, investigation and malware analysis processes, and security automation. No prerequisites.

Exam domains

  • Fundamentals: 20%
  • Techniques: 30%
  • Processes: 30%
  • Automation: 20%

120 minutes, US$400 per attempt, Pearson VUE test centre or online, certification valid for three years. Cisco does not publish a fixed passing score.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Cisco 350-201 CBRCOR pack?

228 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.