CiscoProfessional level350-201

350-201 exam dumps: 289 free Cisco CBRCOR (CyberOps Professional Core) practice questions

Free 350-201 practice questions for the Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies exam, with the correct answer and a full explanation for every option. Read the first 10 below, browse all 289 by number, or take a timed practice exam.

Question bank last updated February 2025

Free 350-201 practice questions

Questions 1 to 10 of 289

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

350-201 Question 1

Select 3

A security analyst at your organization is tasked with evaluating the effectiveness of the current cybersecurity framework. As part of the process, they must identify the three pillars of the CIA triad to ensure a robust security posture. Which of the following components are part of the CIA triad?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Accountability

  4. D

    Availability

  5. E

    Authentication

  6. F

    Non-repudiation

Show answer and explanation

Correct answers: A, B, D

Explanation

The CIA triad is a foundational concept in cybersecurity that stands for Confidentiality, Integrity, and Availability. These three components are essential for designing and maintaining secure systems. Confidentiality ensures that only authorized users can access sensitive information. Integrity guarantees that data remains unaltered and trustworthy. Availability ensures that authorized individuals can access information and resources when needed. While concepts like accountability, authentication, and non-repudiation are important in cybersecurity, they do not form part of the CIA triad framework.

  • A. Correct.

    Confidentiality is a core component of the CIA triad and ensures that sensitive information is protected from unauthorized access.

  • B. Correct.

    Integrity is a key element of the CIA triad, focusing on ensuring that data is accurate, consistent, and not altered by unauthorized individuals.

  • C. Incorrect.

    Accountability is an important security principle, but it is not one of the three components of the CIA triad.

  • D. Correct.

    Availability is a critical component of the CIA triad, which ensures that authorized users have access to information and resources when needed.

  • E. Incorrect.

    Authentication is a fundamental security mechanism, but it is not part of the CIA triad. It is typically a means to enforce confidentiality, integrity, or availability.

  • F. Incorrect.

    Non-repudiation is a vital security concept, especially in digital communications, but it is not one of the three pillars of the CIA triad.

350-201 Question 2

Select 3

A cybersecurity administrator is tasked with implementing a Zero Trust architecture in their network environment. As part of the initial steps, they need to identify the key principles of the Zero Trust model to ensure proper implementation. Which of the following are core principles of the Zero Trust framework?

  1. A

    Always trust devices that are part of the internal network

  2. B

    Verify explicitly by using strong authentication methods

  3. C

    Assume breach and design defenses accordingly

  4. D

    Enforce least privilege access for users and devices

  5. E

    Allow unrestricted access to critical systems for faster troubleshooting

Show answer and explanation

Correct answers: B, C, D

Explanation

The Zero Trust model is built on the principles of 'never trust, always verify,' assuming breach, and enforcing least privilege access to minimize security risks. These principles collectively ensure that security is maintained regardless of whether resources are inside or outside the traditional network perimeter.

  • A. Incorrect.

    This option is incorrect because the Zero Trust model operates on the principle of 'never trust, always verify,' even for devices within the internal network.

  • B. Correct.

    This option is correct as verifying explicitly, often through strong authentication and authorization, is a core principle of Zero Trust.

  • C. Correct.

    This option is correct because assuming breach and preparing defenses accordingly is fundamental to the Zero Trust framework to mitigate risks effectively.

  • D. Correct.

    This option is correct as enforcing least privilege ensures that users and devices only have access to the resources they need, reducing the attack surface.

  • E. Incorrect.

    This option is incorrect since unrestricted access contradicts Zero Trust principles, which emphasize controlled and monitored access to critical systems.

350-201 Question 3

Single answer

You are a cybersecurity analyst tasked with implementing a zero-trust security model in your organization. As part of the initial step, you need to ensure proper segmentation and control of network traffic. Which fundamental concept of Cisco Security Technologies would be MOST crucial for achieving this goal?

  1. A

    Micro-segmentation using Cisco TrustSec

  2. B

    Cisco Secure Email Gateway configuration

  3. C

    Deploying endpoint protection with Cisco AMP for Endpoints

  4. D

    Monitoring network traffic using Cisco Stealthwatch

Show answer and explanation

Correct answer: A

Explanation

Zero-trust security relies heavily on network segmentation and strict access controls. Cisco TrustSec is a foundational technology for achieving micro-segmentation, which is a critical component of zero trust. It ensures that network traffic is controlled and authorized based on identity policies, aligning with the zero-trust principles.

  • A. Correct.

    Micro-segmentation using Cisco TrustSec is a fundamental approach in implementing a zero-trust model by segmenting the network and enforcing access policies based on identity, ensuring only authorized traffic flows.

  • B. Incorrect.

    Cisco Secure Email Gateway is focused on email security, which is not directly related to network segmentation or the zero-trust model.

  • C. Incorrect.

    Deploying endpoint protection with Cisco AMP for Endpoints is valuable for endpoint security but does not address network segmentation or the enforcement of a zero-trust model.

  • D. Incorrect.

    Monitoring network traffic using Cisco Stealthwatch helps with detecting and responding to threats but does not enforce segmentation or directly implement the zero-trust model.

350-201 Question 4

Single answer

An organization is implementing a cybersecurity solution using Cisco technologies. During a security review, the security team identifies that they need to establish a foundational security posture by integrating visibility, control, and automation across their environment. Which Cisco framework or architecture should they adopt to meet these requirements?

  1. A

    Cisco SecureX

  2. B

    Cisco Talos Intelligence

  3. C

    Cisco Umbrella

  4. D

    Cisco SD-WAN

Show answer and explanation

Correct answer: A

Explanation

Cisco SecureX is specifically designed to integrate security tools, provide centralized visibility, and enable automation across the security ecosystem, making it the most suitable choice for establishing a foundational security posture. Other options like Talos, Umbrella, and SD-WAN address specific aspects of security or networking but do not meet the broader requirements of integration and automation.

  • A. Correct.

    Cisco SecureX is a cloud-native security platform that provides integration, visibility, automation, and control across Cisco security products and third-party tools, making it ideal for establishing a foundational security posture.

  • B. Incorrect.

    Cisco Talos Intelligence focuses on threat intelligence and research but does not provide the integration and automation capabilities required for a foundational security framework.

  • C. Incorrect.

    Cisco Umbrella is a cloud-delivered security solution focused on DNS-layer security and secure web gateways, but it does not offer comprehensive integration and automation features across the security environment.

  • D. Incorrect.

    Cisco SD-WAN is a software-defined wide-area networking solution that optimizes network connectivity but is not designed as a foundational security architecture.

350-201 Question 5

Single answer

You are a security analyst tasked with analyzing a playbook designed to respond to phishing email incidents. The playbook includes the following steps: 'Email header analysis,' 'URL reputation check,' 'Quarantine email,' and 'User notification.' Which of the following best describes a critical component of this playbook?

  1. A

    The use of an automated system to execute all steps

  2. B

    The inclusion of specific, actionable steps to address the phishing email

  3. C

    The involvement of an external threat intelligence feed

  4. D

    The integration of a machine learning model to predict future phishing attempts

Show answer and explanation

Correct answer: B

Explanation

A playbook's primary purpose is to provide clear, actionable steps for responding to a specific incident type. In this case, the phishing email response playbook includes steps that guide the security team in analyzing, mitigating, and notifying stakeholders about the threat. While other tools and integrations can augment a playbook, the inclusion of actionable steps is the most critical component.

  • A. Incorrect.

    While automation is valuable, it is not a critical requirement for a playbook. Playbooks can also involve manual processes.

  • B. Correct.

    A playbook must include specific, actionable steps to guide the response process effectively. This is a critical component for ensuring consistency and clarity during incident response.

  • C. Incorrect.

    Using an external threat intelligence feed can enhance the playbook but is not mandatory for its creation or functionality.

  • D. Incorrect.

    Machine learning models may provide additional insights or predictions, but they are not essential components of a playbook's structure.

350-201 Question 6

Select 3

A cybersecurity team is tasked with automating their incident response process using a playbook. The team’s playbook includes components such as triggers, conditions, and actions. Which of the following elements are correctly interpreted as key components of a security playbook?

  1. A

    A trigger that initiates the playbook when specific conditions, such as an alert, are met.

  2. B

    A condition that defines contextual parameters, such as the severity of an alert or affected assets.

  3. C

    A manual step requiring an analyst to review and approve every action before execution.

  4. D

    An action that specifies the tasks to be executed, such as isolating a compromised endpoint or blocking an IP address.

  5. E

    A log of all past incidents and their resolutions for reference.

Show answer and explanation

Correct answers: A, B, D

Explanation

A playbook is a predefined workflow that automates incident response processes. Key components include triggers to initiate the playbook, conditions to evaluate the context, and actions to execute specific tasks. These elements work together to streamline and standardize responses to cybersecurity incidents, reducing reaction time and minimizing human error.

  • A. Correct.

    A trigger is a valid component of a playbook as it defines the event or condition that initiates the workflow.

  • B. Correct.

    Conditions are used to determine whether specific criteria are met before proceeding with actions, making them an essential part of a playbook.

  • C. Incorrect.

    While manual interventions can occur in incident response, requiring an analyst to review every action negates the automation purpose of a playbook. Thus, this is not a key playbook component.

  • D. Correct.

    Actions are critical components of a playbook as they define the tasks to be carried out during incident response.

  • E. Incorrect.

    A log of past incidents is useful for reference and analysis but does not constitute a key component of a playbook.

350-201 Question 7

Select 3

You are a security analyst reviewing a playbook created for responding to phishing email incidents. The playbook includes the following components: identifying the malicious email, isolating affected endpoints, notifying affected users, and collecting evidence for further analysis. Which components of the playbook are essential for ensuring proper incident response and mitigation?

  1. A

    Identifying the malicious email

  2. B

    Isolating affected endpoints

  3. C

    Notifying affected users

  4. D

    Configuring network firewall rules

  5. E

    Collecting evidence for further analysis

Show answer and explanation

Correct answers: A, B, E

Explanation

In an effective playbook, components must focus on immediate response actions to mitigate the attack, such as identification, containment, and evidence gathering. While notifying users and firewall configurations are important in broader security contexts, they are not directly critical to phishing mitigation in this scenario.

  • A. Correct.

    Identifying the malicious email is a critical first step to determine the scope and nature of the incident.

  • B. Correct.

    Isolating affected endpoints helps prevent the spread of the phishing attack, making it an essential mitigation step.

  • C. Incorrect.

    While notifying affected users is important, it is not a direct response or mitigation action in this specific incident context.

  • D. Incorrect.

    Configuring network firewall rules, while useful in other scenarios, is not directly relevant in most phishing email responses unless the attack involves malicious traffic.

  • E. Correct.

    Collecting evidence for further analysis ensures that the incident can be properly investigated and lessons learned for future prevention.

350-201 Question 8

Select 3

You are part of a security operations team and are tasked with automating the response to a phishing email incident. The playbook you are reviewing includes steps such as 'Email Header Analysis,' 'URL Reputation Check,' 'Quarantine Email,' and 'Notify Affected Users.' Which of the following are key components of this playbook that ensure an effective and automated response?

  1. A

    Triggers that define when the playbook is initiated

  2. B

    Defined steps for each action to be taken during the response

  3. C

    A list of unaffected users to exclude from notifications

  4. D

    Integration points with tools like email gateways and SIEM platforms

  5. E

    Manual intervention steps to ensure human oversight at every stage

Show answer and explanation

Correct answers: A, B, D

Explanation

An effective playbook for phishing email incidents should include clearly defined triggers, step-by-step actions, and integration with relevant tools to ensure automation and efficiency. These components allow the playbook to be executed systematically and consistently. Manual steps can be included sparingly but are not required at every stage in an automated playbook.

  • A. Correct.

    Triggers are essential as they define the conditions under which the playbook is executed, ensuring timely response to incidents.

  • B. Correct.

    Defined steps outline the sequence of actions to be performed, making the playbook actionable and structured.

  • C. Incorrect.

    While excluding unaffected users could be important in some scenarios, it is not a core component of the playbook itself. This is more of a detail within a specific action in the playbook.

  • D. Correct.

    Integration points with relevant tools like email gateways and SIEM platforms are critical for automating processes and gathering necessary data.

  • E. Incorrect.

    Manual intervention at every stage negates the purpose of automation in playbooks. While human oversight might be needed at key decision points, it is not a requirement for every step.

350-201 Question 9

Select 3

An organization has observed a spike in suspicious outbound traffic from multiple endpoints. According to the incident response playbook, the team needs to analyze network traffic for potential data exfiltration and identify the affected endpoints. Which tools should be used to fulfill the requirements outlined in the playbook?

  1. A

    NetFlow or Secure Network Analytics

  2. B

    Cisco Advanced Malware Protection (AMP) for Endpoints

  3. C

    Wireshark or packet capture tools

  4. D

    Cisco Umbrella

  5. E

    Cisco Identity Services Engine (ISE)

  6. F

    Endpoint Detection and Response (EDR) tools

Show answer and explanation

Correct answers: A, C, F

Explanation

To address the playbook scenario, tools like NetFlow or Secure Network Analytics, Wireshark, and EDR are essential. NetFlow or Secure Network Analytics offers high-level visibility into network traffic, Wireshark provides granular packet-level analysis, and EDR tools help investigate and remediate affected endpoints. These tools together fulfill the requirements of detecting data exfiltration and identifying impacted endpoints.

  • A. Correct.

    NetFlow or Secure Network Analytics provides visibility into network traffic patterns and can help identify anomalous or suspicious outbound traffic indicative of data exfiltration.

  • B. Incorrect.

    Cisco Advanced Malware Protection (AMP) for Endpoints focuses on malware detection and remediation on endpoints, but it does not analyze network traffic for data exfiltration.

  • C. Correct.

    Wireshark or packet capture tools allow for detailed inspection of network traffic, making them essential for analyzing data exfiltration incidents.

  • D. Incorrect.

    Cisco Umbrella provides DNS-layer security and blocks malicious domains, but it is not designed for in-depth traffic analysis during an incident response.

  • E. Incorrect.

    Cisco Identity Services Engine (ISE) focuses on network access control and policy enforcement but does not provide tools for analyzing network traffic or endpoints during incidents.

  • F. Correct.

    Endpoint Detection and Response (EDR) tools help identify and investigate compromised endpoints, making them useful for addressing affected endpoints as per the playbook.

350-201 Question 10

Select 2

During an active ransomware attack, a cybersecurity team is following a playbook for incident response. The playbook specifies identifying the affected systems, isolating them from the network, and collecting forensic evidence. Which tools would be most appropriate to use in this scenario?

  1. A

    Cisco Secure Endpoint

  2. B

    Cisco Umbrella

  3. C

    Wireshark

  4. D

    Cisco Secure Malware Analytics (Threat Grid)

  5. E

    Cisco Secure Firewall

Show answer and explanation

Correct answers: A, D

Explanation

The playbook specifies identifying affected systems, isolating them from the network, and collecting forensic evidence. Cisco Secure Endpoint is an effective tool for identifying and isolating compromised devices, while Cisco Secure Malware Analytics (Threat Grid) supports forensic analysis of malware. These tools align closely with the steps outlined in the playbook.

  • A. Correct.

    Cisco Secure Endpoint is a suitable tool for identifying affected systems and isolating them from the network, as it provides endpoint detection and response (EDR) capabilities.

  • B. Incorrect.

    Cisco Umbrella is primarily used for DNS-layer security and blocking malicious domains but does not directly assist in identifying or isolating affected systems or collecting forensic evidence during an active ransomware attack.

  • C. Incorrect.

    Wireshark is a network protocol analyzer that can capture network traffic for analysis but does not provide direct tools for identifying or isolating affected systems or collecting forensic evidence in this scenario.

  • D. Correct.

    Cisco Secure Malware Analytics (Threat Grid) is highly useful for analyzing suspicious files and collecting forensic evidence, which aligns with the playbook's steps for this scenario.

  • E. Incorrect.

    Cisco Secure Firewall is primarily used for perimeter defense and segmentation. While it can block malicious traffic, it is not directly relevant to identifying affected systems or collecting forensic evidence during an active ransomware attack.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

All 289 350-201 practice questions

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them.

  1. 1.A security analyst at your organization is tasked with evaluating the effectiveness of the current...
  2. 2.A cybersecurity administrator is tasked with implementing a Zero Trust architecture in their network...
  3. 3.You are a cybersecurity analyst tasked with implementing a zero-trust security model in your organization. As...
  4. 4.An organization is implementing a cybersecurity solution using Cisco technologies. During a security review,...
  5. 5.You are a security analyst tasked with analyzing a playbook designed to respond to phishing email incidents....
  6. 6.A cybersecurity team is tasked with automating their incident response process using a playbook. The team’s...
  7. 7.You are a security analyst reviewing a playbook created for responding to phishing email incidents. The...
  8. 8.You are part of a security operations team and are tasked with automating the response to a phishing email...
  9. 9.An organization has observed a spike in suspicious outbound traffic from multiple endpoints. According to the...
  10. 10.During an active ransomware attack, a cybersecurity team is following a playbook for incident response. The...
  11. 11.During a cybersecurity incident, a playbook recommends isolating a potentially compromised endpoint and...
  12. 12.Your organization has experienced a malware outbreak, and the incident response playbook recommends isolating...
  13. 13.A security analyst at a retail company notices that several user accounts are exhibiting unauthorized...
  14. 14.An organization has detected unusual traffic patterns indicating a Distributed Denial of Service (DDoS)...
  15. 15.You are a cybersecurity analyst investigating a Distributed Denial of Service (DDoS) attack targeting your...
  16. 16.You are working as a cybersecurity analyst for an organization and receive an alert from your SIEM system...
  17. 17.A financial services company is implementing strict compliance measures to protect customer payment data and...
  18. 18.A financial institution is implementing a system to ensure compliance with industry-specific regulatory...
  19. 19.A company in the financial services industry is planning to implement a cybersecurity framework to ensure...
  20. 20.A company is preparing to implement a compliance program to meet regulatory requirements. The company...
  21. 21.A financial institution has implemented multiple layers of security to protect its sensitive customer data....
  22. 22.A medium-sized enterprise recently experienced a ransomware attack that caused significant financial and...
  23. 23.A medium-sized company recently suffered a ransomware attack that disrupted their operations and resulted in...
  24. 24.A medium-sized e-commerce company has recently implemented Cisco security technologies to enhance its...
  25. 25.A financial institution is conducting a risk analysis to secure their customer data stored on an internal...
  26. 26.You are conducting a risk analysis for a financial institution's online banking platform. During the...
  27. 27.A financial institution is conducting a risk analysis as part of its cybersecurity strategy. During the...
  28. 28.A financial institution has recently implemented a risk analysis process to strengthen its cybersecurity...
  29. 29.A financial institution has detected unusual outbound traffic from one of its internal servers. The Security...
  30. 30.A cybersecurity analyst at your organization detects unusual outbound traffic from a server that might...
  31. 31.Your organization experiences a ransomware attack that encrypts critical files, and the attackers demand...
  32. 32.A financial institution has detected unusual outbound traffic from their network, which they suspect is...
  33. 33.An organization is reviewing its incident response metrics to improve its overall security posture. Which of...
  34. 34.During a post-incident review, the cybersecurity team evaluates their incident response metrics to identify...
  35. 35.A company’s security team is evaluating their incident response process using key metrics. They identify that...
  36. 36.A security operations team is evaluating its incident response metrics after a recent series of ransomware...
  37. 37.An organization is planning to migrate its IT infrastructure to the cloud. They want to retain complete...
  38. 38.A security team is tasked with deploying a cloud environment that provides exclusive access to infrastructure...
  39. 39.Your organization is planning to migrate its workloads to the cloud while maintaining strict control over...
  40. 40.An organization is planning to migrate its on-premises infrastructure to the cloud. It wants to use a cloud...
  41. 41.A cybersecurity team is tasked with managing and securing a hybrid cloud environment that utilizes both IaaS...
  42. 42.A company is migrating its operations to the cloud and is evaluating the security responsibilities for its...
  43. 43.A company is migrating its applications to the cloud and is evaluating the security operations considerations...
  44. 44.A cybersecurity team is tasked with ensuring proper security controls for their organization's applications...
  45. 45.A security analyst is investigating unusual outbound traffic from a corporate network. After analyzing...
  46. 46.You are a cybersecurity analyst tasked with investigating a potential data exfiltration incident in your...
  47. 47.A security analyst is configuring an Intrusion Prevention System (IPS) on a Cisco Firepower device. The...
  48. 48.Your organization has recently deployed Cisco Secure Endpoint (formerly AMP) across all endpoints. As part of...
  49. 49.A financial company is experiencing a surge in fraudulent transactions and is looking to implement a...
  50. 50.A financial organization has noticed an increase in fraudulent transaction patterns and needs to identify...
  51. 51.A midsize enterprise is experiencing frequent unauthorized login attempts on their internal systems. The...
  52. 52.A financial organization is experiencing an increasing number of fraudulent transactions and wants to...
  53. 53.Your team is tasked with deploying a new web application using a pre-configured machine image. As part of the...
  54. 54.An organization is preparing to deploy a web application on a cloud-based infrastructure. To ensure the...
  55. 55.You are tasked with deploying a machine image for a new web application in your organization's cloud...
  56. 56.Your organization is preparing to deploy a set of virtual machines to a cloud environment. To ensure...
  57. 57.A financial organization wants to evaluate the security posture of its recently deployed cloud-based web...
  58. 58.A security analyst is tasked with evaluating the security posture of a mission-critical server within the...
  59. 59.A financial organization is conducting an evaluation of the security posture of a newly deployed web...
  60. 60.You are tasked with evaluating the security posture of a critical company asset. The asset is a web...
  61. 61.You are tasked with evaluating the security posture of a company’s network environment. During the...
  62. 62.Your organization recently conducted a vulnerability assessment and identified several gaps in its security...
  63. 63.You are tasked with evaluating the security posture of a corporate network. After conducting an assessment,...
  64. 64.You are tasked with evaluating the security controls of a company’s network environment. During your...
  65. 65.You are tasked with hardening an organization's systems to align with industry standards. Which resources...
  66. 66.A cybersecurity analyst is tasked with hardening a network's systems to align with industry standards and...
  67. 67.An enterprise security team is tasked with hardening their systems to meet industry standards and best...
  68. 68.While working as a cybersecurity engineer for an organization, you are tasked with hardening a critical...
  69. 69.During a routine vulnerability assessment of your network, you discover that several Cisco devices are...
  70. 70.A healthcare organization has discovered a critical vulnerability in one of its on-premises web servers,...
  71. 71.A healthcare organization has recently discovered that its patient management system is vulnerable to a...
  72. 72.You are a security administrator for a medium-sized organization. During a routine vulnerability scan, you...
  73. 73.A financial organization has recently deployed a new web server in its DMZ for customer transactions. The...
  74. 74.A company's cybersecurity team is tasked with hardening a newly deployed web server running on Cisco...
  75. 75.Your organization has deployed a new Cisco ASA firewall to secure a branch office. After the initial...
  76. 76.Your organization has recently deployed a Cisco Firepower Threat Defense (FTD) firewall in its network....
  77. 77.You are a security administrator tasked with segmenting a corporate network to reduce the attack surface and...
  78. 78.An organization has recently experienced a data breach where attackers moved laterally across the network to...
  79. 79.A company’s network has recently experienced a ransomware attack that spread laterally from one compromised...
  80. 80.Your company has recently deployed Cisco Firepower Threat Defense (FTD) appliances to improve network...
  81. 81.A cybersecurity analyst has been tasked with strengthening the security posture of a corporate network. The...
  82. 82.Your organization has recently experienced a security breach caused by attackers exploiting unused open ports...
  83. 83.Your company’s network infrastructure has recently been targeted with multiple unauthorized access attempts....
  84. 84.An organization has recently experienced a network breach due to unauthorized access. As a cybersecurity...
  85. 85.Your organization is implementing a DevSecOps pipeline for application development. Security testing has been...
  86. 86.A financial services company is migrating its infrastructure to a DevSecOps model to enhance security...
  87. 87.Your organization is adopting a DevSecOps approach to integrate security into the software development...
  88. 88.A cybersecurity team is integrating DevSecOps principles into their CI/CD pipeline to enhance security. Which...
  89. 89.An organization is using a Threat Intelligence Platform (TIP) to enhance its cybersecurity operations. The...
  90. 90.An organization is leveraging a Threat Intelligence Platform (TIP) to improve its security posture. The...
  91. 91.Your organization recently deployed a Threat Intelligence Platform (TIP) to improve its cybersecurity...
  92. 92.A cybersecurity team uses a Threat Intelligence Platform (TIP) to enhance their incident response workflow....
  93. 93.A company uses Cisco SecureX and Cisco Secure Network Analytics to monitor its network. Recently, the company...
  94. 94.Your organization uses Cisco SecureX and Cisco Secure Network Analytics to monitor network traffic and detect...
  95. 95.An organization has deployed Cisco SecureX to integrate its security tools and enhance threat visibility. The...
  96. 96.A security analyst working for an organization notices an unusual spike in outbound traffic from multiple...
  97. 97.A financial organization is implementing a data loss prevention (DLP) strategy to safeguard sensitive...
  98. 98.An organization is implementing a data loss prevention (DLP) solution to protect sensitive customer...
  99. 99.A financial services company wants to enhance its data protection strategy by implementing controls to...
  100. 100.An organization is implementing a Data Loss Prevention (DLP) solution to safeguard sensitive customer...
  101. 101.A financial institution wants to implement a data loss prevention (DLP) strategy to secure sensitive customer...
  102. 102.A company is implementing a Data Loss Prevention (DLP) strategy to protect sensitive information transmitted...
  103. 103.A company is experiencing frequent accidental data leaks due to employees sharing sensitive customer...
  104. 104.An organization wants to prevent sensitive customer data from being shared outside its corporate network. As...
  105. 105.A security analyst is tasked with deploying endpoint protection on all hosts within their organization to...
  106. 106.Your organization has deployed Cisco Secure Endpoint to protect endpoints against malware and advanced...
  107. 107.A security analyst is investigating a compromised host within the network. They suspect that malware has been...
  108. 108.An organization suspects that a host within its network has been compromised and is communicating with a...
  109. 109.A company is experiencing a surge in malicious network activity targeting internal servers. As part of the...
  110. 110.You are configuring a Cisco Firepower Threat Defense (FTD) device to secure a corporate network. The network...
  111. 111.During an internal security assessment, you are tasked with configuring Cisco Secure Firewall to mitigate...
  112. 112.You are a security engineer tasked with monitoring and securing a company's network infrastructure. While...
  113. 113.Your organization is deploying Cisco Secure Firewall Threat Defense (FTD) to protect its web application from...
  114. 114.An organization has deployed Cisco Secure Firewall and is using application filtering to control access to...
  115. 115.A company is deploying a new web-based application that handles sensitive customer data. The security team...
  116. 116.Your organization recently deployed Cisco Secure Workload to monitor application behavior and secure...
  117. 117.Your organization is using Cisco Umbrella to secure cloud-based applications and enforce security policies...
  118. 118.Your organization has recently migrated its workload to a cloud environment. As a cybersecurity engineer, you...
  119. 119.A company is transitioning its on-premises workloads to the cloud. As a cybersecurity expert, you are tasked...
  120. 120.You are a cybersecurity engineer tasked with securing your organization's multi-cloud environment. To achieve...
  121. 121.A cybersecurity analyst is managing a Cisco Firepower system that is generating a high number of false...
  122. 122.An organization has implemented Cisco Secure Firewall and Cisco Secure Endpoint to protect its network and...
  123. 123.Your organization has implemented Cisco Secure Firewall to monitor and block malicious traffic. Recently, a...
  124. 124.A security analyst at your organization has noticed an increased number of false positives being generated by...
  125. 125.An enterprise security team is struggling to process and analyze data from multiple sources, such as...
  126. 126.Your company recently implemented a Cisco Secure Network Analytics solution to monitor and detect threats in...
  127. 127.A security operations team is tasked with managing a large volume of security event logs generated by devices...
  128. 128.An organization is deploying a new Security Information and Event Management (SIEM) solution to enhance their...
  129. 129.A cybersecurity team is leveraging a SIEM tool to enhance their organization's threat detection capabilities....
  130. 130.Your organization uses a Security Information and Event Management (SIEM) tool to monitor and analyze...
  131. 131.A cybersecurity analyst at your organization is using a SIEM tool to detect potential threats within the...
  132. 132.An organization uses a SIEM tool to monitor and analyze security events across its network. The security team...
  133. 133.A cybersecurity team is dealing with a high-severity phishing incident in which multiple users have reported...
  134. 134.A security operations team has detected a suspicious file being downloaded by multiple users in the...
  135. 135.A financial organization experiences frequent phishing attacks targeting its employees. The Security...
  136. 136.A financial organization has recently experienced a phishing attack that resulted in compromised employee...
  137. 137.You are a cybersecurity analyst managing Cisco SecureX. After detecting a spike in malware activity, you use...
  138. 138.You are tasked with presenting security metrics from the Cisco SecureX dashboard to various stakeholder...
  139. 139.You are a cybersecurity analyst tasked with presenting security dashboard data to stakeholders. The dashboard...
  140. 140.You are a security analyst using Cisco SecureX to monitor your organization's security posture. A recent...
  141. 141.Your organization uses a SIEM solution integrated with a User and Entity Behavior Analytics (UEBA) tool to...
  142. 142.A company’s SIEM platform has flagged anomalous behavior from a user account, including multiple failed login...
  143. 143.You are a security analyst reviewing SIEM data integrated with a User and Entity Behavior Analytics (UEBA)...
  144. 144.As a security analyst, you are using a SIEM platform integrated with UEBA capabilities to monitor user and...
  145. 145.A financial organization uses Cisco Secure Endpoint to monitor user behavior. An alert is triggered for a...
  146. 146.A security operations team is using Cisco Secure Endpoint to monitor user behavior alerts. An alert is...
  147. 147.A financial organization uses Cisco Secure Analytics to monitor user behavior. The security team receives an...
  148. 148.You are a cybersecurity analyst monitoring user behavior in Cisco Secure Endpoint. You receive an alert that...
  149. 149.During a network security investigation, an analyst uses packet capture tools, traffic analysis tools, and...
  150. 150.You are investigating a potential data exfiltration incident in your network. To identify the source of the...
  151. 151.A cybersecurity analyst is troubleshooting a suspected data exfiltration incident within their network. They...
  152. 152.A network administrator is troubleshooting an ongoing issue with intermittent connectivity on a critical...
  153. 153.You are a cybersecurity analyst investigating a potential data exfiltration incident. You have a packet...
  154. 154.You are investigating an incident where a suspected malicious file was downloaded from a website. A packet...
  155. 155.While investigating a suspected data exfiltration incident, you analyze a packet capture (PCAP) file. You...
  156. 156.You are analyzing a packet capture (PCAP) file to investigate a potential data exfiltration incident. During...
  157. 157.A cybersecurity analyst is troubleshooting an issue where a Cisco Secure Endpoint detection rule is not...
  158. 158.You are managing a Cisco Secure Endpoint (formerly AMP for Endpoints) deployment in your organization....
  159. 159.A security analyst is investigating an issue where a detection rule in Cisco Secure Endpoint (formerly AMP...
  160. 160.A security analyst is troubleshooting an existing detection rule in Cisco Secure Endpoint (formerly AMP for...
  161. 161.A financial institution experienced a data breach where attackers used phishing emails to harvest employee...
  162. 162.A security analyst is investigating a recent cyberattack on their organization's network. During the...
  163. 163.A cybersecurity analyst is investigating an attack where the adversary bypassed endpoint defenses, escalated...
  164. 164.A cybersecurity analyst is investigating a recent data breach. During the analysis, they identify that the...
  165. 165.Your organization has recently implemented Cisco SecureX to improve its security operations and automate...
  166. 166.An organization is implementing a new incident response (IR) process and wants to align it with Cisco's...
  167. 167.A security operations center (SOC) analyst is investigating a potential data breach in a company's network....
  168. 168.You are a security analyst for a mid-sized organization. During a routine review of your incident response...
  169. 169.A security analyst is tasked with assessing the potential threats to a newly deployed web application. As...
  170. 170.A financial institution is building a new online banking platform and has hired a security team to evaluate...
  171. 171.A financial institution is developing a new web application that handles sensitive customer data such as...
  172. 172.You are a cybersecurity analyst tasked with reviewing a threat model for a financial application. During the...
  173. 173.Your organization has detected unusual outbound traffic from multiple endpoints at odd hours, suggesting a...
  174. 174.A security analyst at your organization identifies suspicious activity involving an employee's endpoint,...
  175. 175.You are a cybersecurity analyst at a financial institution and receive an alert about suspicious login...
  176. 176.An organization using Cisco Secure Endpoint has detected unusual activity on a host. The security team...
  177. 177.You are a security analyst in a SOC (Security Operations Center), and a suspicious file has been flagged on a...
  178. 178.You are a cybersecurity analyst tasked with analyzing a suspicious file detected in your organization's...
  179. 179.A security analyst at a financial institution is investigating a suspicious file detected on an employee's...
  180. 180.A security analyst is tasked with analyzing a suspicious file discovered on a corporate endpoint. The analyst...
  181. 181.While investigating a potential data breach, your cybersecurity team suspects malicious activity within...
  182. 182.During a cybersecurity investigation, you are tasked with analyzing suspicious network traffic. You need to...
  183. 183.During a security investigation, you suspect that an internal workstation is communicating with a malicious...
  184. 184.A security analyst is investigating unusual traffic patterns and needs to extract packets for further...
  185. 185.During an investigation, your team identifies a suspicious binary file downloaded onto a compromised...
  186. 186.While investigating a suspicious executable file found on a company server, you are tasked with performing...
  187. 187.A security analyst has been tasked with performing reverse engineering on a suspicious executable file that...
  188. 188.An organization detects suspicious activity on its network and captures a binary file suspected to be...
  189. 189.As a security analyst, you are tasked with analyzing a suspicious file that was flagged by your...
  190. 190.During a cybersecurity investigation, you suspect a file contains malicious behavior. You decide to perform...
  191. 191.You are investigating a suspicious file and decide to perform dynamic malware analysis using a sandbox...
  192. 192.You are tasked with analyzing a suspicious file that was flagged by your organization's endpoint detection...
  193. 193.You are a cybersecurity analyst investigating a suspicious file flagged by the Endpoint Detection and...
  194. 194.A cybersecurity analyst at a company receives a suspicious file from a user reporting unusual system...
  195. 195.A security analyst is investigating a suspicious file detected on a corporate endpoint. Initial dynamic...
  196. 196.During an incident response investigation, a security analyst discovers a suspicious file that has evaded...
  197. 197.You are a security analyst tasked with performing static malware analysis on a suspicious executable file...
  198. 198.A cybersecurity analyst receives a suspicious executable file that is suspected to be malware. To perform...
  199. 199.A security analyst is tasked with performing a static analysis of a suspicious executable file found in the...
  200. 200.You are tasked with performing static malware analysis on a suspicious file discovered in your organization's...
  201. 201.You are a cybersecurity analyst tasked with analyzing data from a recent security incident involving...
  202. 202.You are a cybersecurity analyst investigating a recent breach in your organization's network. After analyzing...
  203. 203.You are a cybersecurity analyst in charge of investigating a network intrusion incident. After performing a...
  204. 204.You are a cybersecurity analyst at a mid-sized enterprise. After performing an investigation on a recent...
  205. 205.During a security investigation, a predictive AI system identifies unusual traffic patterns involving a...
  206. 206.During a network security analysis using predictive AI, you notice an unusual spike in outbound traffic from...
  207. 207.You are a security analyst monitoring network traffic using a Cisco security solution that integrates...
  208. 208.A network security team is using a Cisco AI-based predictive analysis tool that monitors traffic patterns for...
  209. 209.A security analyst receives an alert indicating suspicious activity on an employee's laptop. The analyst must...
  210. 210.A cybersecurity analyst receives an alert about suspicious activity on an employee's laptop. Upon...
  211. 211.An organization suspects that a critical endpoint, a company-issued laptop, has been compromised by a...
  212. 212.A cybersecurity analyst receives an alert indicating abnormal file access patterns on a corporate laptop. The...
  213. 213.A security operations team has detected unusual outbound traffic from a critical server. Upon further...
  214. 214.Your organization recently experienced a security breach where an attacker exfiltrated sensitive data. As a...
  215. 215.Your organization has detected unusual outbound traffic from a server that typically handles internal...
  216. 216.A security analyst at your organization is investigating unusual network activity and suspects a potential...
  217. 217.You are investigating a suspicious file in a sandbox environment and have identified unusual network traffic...
  218. 218.You are investigating a suspicious file in a sandbox environment. The sandbox generates the following...
  219. 219.You are analyzing a suspicious file in a sandbox environment to determine its Indicators of Compromise...
  220. 220.You are tasked with analyzing a suspicious file in a Cisco Threat Grid sandbox environment. During the...
  221. 221.Your organization recently detected unusual activity involving a large amount of sensitive customer data...
  222. 222.Your security operations team has detected unusual data exfiltration from an organization's cloud storage....
  223. 223.Your organization has detected unusual activity in its cloud-hosted database, and there is a suspicion of...
  224. 224.A company uses a hybrid cloud environment to store sensitive customer data. Recently, the security team...
  225. 225.A financial company has recently conducted a vulnerability scan and discovered several critical...
  226. 226.Your organization recently conducted a vulnerability assessment, which revealed that a critical web server is...
  227. 227.A network administrator discovers that a critical server in the organization's infrastructure is running...
  228. 228.An organization has identified several high-risk vulnerabilities during a routine security assessment of its...
  229. 229.A financial organization has discovered a critical vulnerability in one of its web applications after...
  230. 230.A security analyst at your organization has identified a critical vulnerability in an internally hosted web...
  231. 231.A cybersecurity analyst is reviewing a vulnerability report for a web application used by the organization....
  232. 232.An organization has identified a critical vulnerability in a web application used to process sensitive...
  233. 233.Your organization wants to automate security policy deployment across its network using Cisco SecureX...
  234. 234.An organization has implemented Cisco SecureX to streamline its security operations. The security team wants...
  235. 235.You are tasked with improving the efficiency of your organization’s incident response process by automating...
  236. 236.Your organization uses Cisco SecureX orchestration to automate threat response workflows. A recent phishing...
  237. 237.Your cybersecurity team has recently deployed a SOAR platform to streamline incident response. During a...
  238. 238.A cybersecurity team is evaluating SOAR platforms to improve their incident response processes. They want a...
  239. 239.An organization is deploying a Security Orchestration, Automation, and Response (SOAR) platform to enhance...
  240. 240.An organization has deployed a Security Orchestration, Automation, and Response (SOAR) platform to streamline...
  241. 241.You are tasked with analyzing a Python script used to automate the addition of IP addresses to a firewall...
  242. 242.You are tasked with analyzing a Python script used to automate the retrieval of security logs from a Cisco...
  243. 243.A network administrator is using a Python script to extract logs from a Cisco Secure Firewall via its REST...
  244. 244.A cybersecurity analyst is tasked with analyzing a Python script used to automate the retrieval of logs from...
  245. 245.You are tasked with automating the process of extracting and analyzing security alerts from a SIEM system to...
  246. 246.You are a security analyst tasked with automating the process of identifying and isolating suspicious IP...
  247. 247.You are tasked with automating a task in the Security Operations Center (SOC) to retrieve the latest security...
  248. 248.You are tasked with automating the task of monitoring failed login attempts across multiple servers in your...
  249. 249.You are analyzing a suspicious data file extracted during a cybersecurity investigation. The contents of the...
  250. 250.A security analyst is reviewing logs from an application firewall that exports logs in various data formats....
  251. 251.A cybersecurity analyst is reviewing logs from a web application firewall (WAF) and notices that the data is...
  252. 252.You are analyzing logs from a Cisco Secure Firewall, which are exported in a structured format. The logs need...
  253. 253.A security operations team is using a SOAR platform to manage incident response processes. They are...
  254. 254.A cybersecurity team is using a Cisco SOAR platform to manage their incident response process. They want to...
  255. 255.A security operations team is deploying a SOAR platform to improve their incident response process. They want...
  256. 256.A security operations team is using a SOAR platform to manage incident response workflows. They aim to reduce...
  257. 257.You are configuring a custom integration with Cisco SecureX using its REST API to automate a security...
  258. 258.You are integrating a third-party threat intelligence platform with Cisco SecureX through its API. During the...
  259. 259.A team is integrating a Cisco SecureX API into their security automation workflow. During testing, they...
  260. 260.A security analyst is integrating a third-party threat intelligence platform with Cisco SecureX using APIs....
  261. 261.While configuring an integration with a Cisco REST API, you receive a response code '401 Unauthorized' during...
  262. 262.A security analyst is working with a REST API to automate the retrieval of threat intelligence data. During...
  263. 263.A security administrator is using a REST API to automate configurations for a Cisco secure network. During...
  264. 264.While troubleshooting an issue with a Cisco security device that uses REST APIs, you observe that the API...
  265. 265.A cybersecurity analyst is investigating unusual HTTP traffic and inspects an HTTP response from a suspicious...
  266. 266.You are investigating a potential security incident involving a web application. During your analysis, you...
  267. 267.A security analyst is reviewing the HTTP response from a suspicious web server. The response includes the...
  268. 268.While investigating a potential data breach, a cybersecurity analyst reviews an HTTP response from a web...
  269. 269.A cybersecurity team is developing a script to interact with a Cisco API for automating security operations....
  270. 270.A company is developing a custom application that interfaces with a Cisco Secure Firewall Management Center...
  271. 271.You are tasked with securing API access for a Cisco SecureX integration. The security requirement is to use a...
  272. 272.A cybersecurity analyst is tasked with securing API access for a web application that integrates with Cisco...
  273. 273.You are investigating a potential unauthorized modification to a critical configuration file on a Linux-based...
  274. 274.You are troubleshooting a potential security issue on a Linux-based server. You suspect that a malicious...
  275. 275.During a cybersecurity investigation, you are analyzing a compromised Linux server. To locate a suspicious...
  276. 276.You are investigating a potential security incident on a Linux-based server. You need to locate a file named...
  277. 277.During a security assessment of your organization's CI/CD pipeline, you are tasked with identifying the...
  278. 278.A cybersecurity team is implementing a CI/CD pipeline to automate the deployment of a new web application....
  279. 279.A security analyst is tasked with identifying vulnerable stages in the CI/CD pipeline of a company’s software...
  280. 280.A security analyst is tasked with integrating security checks into the CI/CD pipeline for a development team....
  281. 281.Your organization is implementing DevOps practices to improve its cybersecurity posture. As part of this...
  282. 282.An organization is implementing DevOps practices to improve the development and deployment of security rules...
  283. 283.A security operations team is adopting DevOps practices to improve their ability to respond to threats in...
  284. 284.A security team is collaborating with the development and operations teams to implement DevOps practices...
  285. 285.A cybersecurity engineer is tasked with deploying and managing configurations for a multi-cloud...
  286. 286.A cybersecurity team is tasked with ensuring consistent deployment of firewall configurations across multiple...
  287. 287.A cybersecurity engineer is tasked with deploying a secure and scalable application on a cloud...
  288. 288.A security engineer is deploying infrastructure in a multi-cloud environment using Infrastructure as Code...
  289. 289.

350-201 exam dumps FAQ

Are these 350-201 dumps real exam questions?

No. These are original practice questions written to the Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies exam objectives, not questions copied from a live exam. Memorising leaked questions violates Cisco's candidate agreement and stops working the moment the question pool rotates. Use this bank to check your understanding of each domain and to find the topics you still need to study.

How many 350-201 practice questions are there?

289 questions, each with the correct answer, an explanation of the answer, and a note on why every other option is wrong. The first 10 are on this page and every question has its own page linked below.

Are the 350-201 exam dumps free?

Yes. Every question, answer and explanation on this page and the linked question pages is free to read without an account. A free HydraNode account adds timed practice exams, scoring and progress tracking across attempts.

How do I take a timed 350-201 practice test?

Sign in and start the Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies exam on HydraNode. A session gives you 75 questions drawn from this bank in 120 minutes, then a score report with a per-question review.