Official Bank 0/139

Performing CyberOps Using Core Security Technologies (CBRCOR) Exam (350-201) - Cisco Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
139 Total Questions
1
Question
DRAG DROP Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.

Exhibit

Prev Step Recover System Remediation Next Step
Update IDS/PS Reimage Collect Logs Categorize
& Firewall Incident Incident Identify Request Packet Remove Determine Patch Targeted Capture Temporary Methods Systems Containment
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
An engineer receives an incident ticket with hundreds of intrusion alerts that require investigation. An analysis of the incident log shows that the alerts are from trusted IP addresses and internal devices. The final incident report stated that these alerts were false positives and that no intrusions were detected. What action should be taken to harden the network?
Options
A Configure reverse port forwarding on the IPS
B Move the IPS to before the firewall facing the outside network
C Configure the proxy service on the IPS
D Move the IPS to after the firewall facing the internal network
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)
Select 2
Options
A log in from a first-seen country
B increased number of sent mails
C log in during non-working hours
D email forwarding to an external domain
E domain belongs to a competitor
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit.

Exhibit

A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end-user community?
Options
A Increase the application cache of the total pool of active clients that call the API
B Add restrictions on the edge router on how often a single client can access the API
C Reduce the amount of data that can be fetched from the total pool of active clients that call the API
D Limit the number of API calls that a single client is allowed to make
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Refer to the exhibit.

Exhibit

An organization is using an internal application for printing documents that requires a separate registration on the website. The application allows format-free user creation, and users must match these required conditions to comply with the company’s user creation policy: minimum length: 3 usernames can only use letters, numbers, dots, and underscores usernames cannot begin with a number The application administrator has to manually change and track these daily to ensure compliance. An engineer is tasked to implement a script to automate the process according to the company user creation policy. The engineer implemented this piece of code within the application, but users are still able to create format-free usernames. Which change is needed to apply the restrictions?
Options
A modify code to force the restrictions, def force_user(username, minlen)
B automate the restrictions def automate_user(username, minlen)
C validate the restrictions, def validate_user(username, minlen)
D modify code to return error on restrictions def return false_user(username, minlen)
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.