Free 350-201 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions

Free preview: 20 questions.

Already purchased? Log in

CISCO 350-201

View Mode
Q: 1
A company’s web server availability was breached by a DDoS attack and was offline for 3 hours because it was not deemed a critical asset in the incident response playbook. Leadership has requested a risk assessment of the asset. An analyst conducted the risk assessment using the threat sources, events, and vulnerabilities. Which additional element is needed to calculate the risk?
Options
Q: 2
What is needed to assess risk mitigation effectiveness in an organization?
Options
Q: 3
The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security specialist to analyze. Which step should be taken at this stage?
Options
Q: 4
What is the purpose of hardening systems?
Options
Q: 5
Refer to the exhibit. CISCO 350-201 question An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon – Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?
Options
Q: 6
An engineer is investigating several cases of increased incoming spam emails and suspicious emails from the HR and service departments. While checking the event sources, the website monitoring tool showed several web scraping alerts overnight. Which type of compromise is indicated?
Options
Q: 7
Refer to the exhibit. CISCO 350-201 question An engineer is analyzing this Vlan0386-int12-117.pcap file in Wireshark after detecting a suspicious network activity. The origin header for the direct IP connections in the packets was initiated by a google chrome extension on a WebSocket protocol. The engineer checked message payloads to determine what information was being sent off-site but the payloads are obfuscated and unreadable. What does this STIX indicate?
Options
Q: 8
What do 2xx HTTP response codes indicate for REST APIs?
Options
Q: 9
An engineer returned to work and realized that payments that were received over the weekend were sent to the wrong recipient. The engineer discovered that the SaaS tool that processes these payments was down over the weekend. Which step should the engineer take first?
Options
Q: 10
The SIEM tool informs a SOC team of a suspicious file. The team initializes the analysis with an automated sandbox tool, sets up a controlled laboratory to examine the malware specimen, and proceeds with behavioral analysis. What is the next step in the malware analysis process?
Options
Q: 11
Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)
Options
Q: 12
Refer to the exhibit. CISCO 350-201 question Where are the browser page rendering permissions displayed?
Options
Q: 13
An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)
Options
Q: 14

DRAG DROP Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right. CISCO 350-201 question

Drag & Drop
Q: 15

DRAG DROP Drag and drop the function on the left onto the mechanism on the right. CISCO 350-201 question

Drag & Drop
Q: 16

DRAG DROP Drag and drop the NIST incident response process steps from the left onto the actions that occur in the steps on the right. CISCO 350-201 question

Drag & Drop
Q: 17

DRAG DROP Refer to the exhibit. CISCO 350-201 question The Cisco Secure Network Analytics (Stealthwatch) console alerted with “New Malware Server Discovered” and the IOC indicates communication from an end-user desktop to a Zeus C&C Server. Drag and drop the actions that the analyst should take from the left into the order on the right to investigate and remediate this IOC. CISCO 350-201 question

Drag & Drop
Q: 18

DRAG DROP Drag and drop the mitigation steps from the left onto the vulnerabilities they mitigate on the right. CISCO 350-201 question

Drag & Drop
Q: 19

DRAG DROP Drag and drop the cloud computing service descriptions from the left onto the cloud service categories on the right. CISCO 350-201 question

Drag & Drop
Q: 20

DRAG DROP Drag and drop the components from the left onto the phases of the CI/CD pipeline on the right. CISCO 350-201 question

Drag & Drop
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE