Fundamentals
Drill 20 practice questions focused entirely on Fundamentals for the Cisco 350-201 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A consortium of five regional hospitals wants to share a common infrastructure to run electronic health record applications. They require that the environment be governed by a shared set of HIPAA-aligned security and compliance policies, and that access be restricted only to the member organizations rather than the general public. Which cloud deployment model best fits these requirements?
A retail company processes credit card transactions through its e-commerce platform and stores cardholder data in a backend database. During an audit, the security team is asked to identify the compliance standard that specifically governs how this data must be protected. Which standard applies to this scenario?
A mid-sized retailer's CISO is building the business case for purchasing a cyber risk insurance policy. During a board meeting, a director asks what the policy is fundamentally intended to accomplish for the organization, given that they already invest heavily in preventive controls. Which statement best describes the primary purpose of cyber risk insurance in this context?
A retail company has implemented layered defenses, an incident response plan, and regular vulnerability management. During a board meeting, the CISO recommends purchasing a cyber risk insurance policy despite these controls. A board member questions why insurance is necessary when strong security controls already exist. Which statement best explains the primary purpose of cyber risk insurance in this context?
A SOC analyst is executing the organization's volumetric DDoS response playbook after monitoring shows a 40 Gbps UDP flood saturating the internet-facing links, causing the public web application to become unreachable. The on-premises firewall and IPS are already overwhelmed and dropping legitimate traffic along with attack traffic. The playbook step reads: 'Mitigate the attack volume before it reaches the enterprise edge.' Which tool or service should the analyst engage to satisfy this playbook step?
A SOC manager reviews the quarterly metrics report and notices that although the mean time to respond (MTTR) has steadily decreased, one attacker maintained access to a compromised server for 47 days before any alert was raised. The manager wants to select the single metric that best quantifies this specific problem and drive improvement toward closing the gap. Which metric most directly measures the length of time an adversary remained undetected inside the environment?
A SOC manager is reviewing quarterly incident response metrics. She notices that while MTTD and MTTR are within targets, a significant number of incidents that were declared 'closed' by the tier-1 team reopened within 30 days because the threat was not fully removed. Which incident response metric should she track to specifically measure and improve this problem?
A SOC manager reviews quarterly metrics and finds that analysts are spending most of their shift closing alerts that turn out to be benign. Legitimate threats are being missed because analysts experience fatigue from the sheer volume of non-actionable tickets. Which incident response metric most directly quantifies this problem, and what improvement action does it point toward?
A U.S.-based SaaS company wants to sell its cloud-hosted collaboration platform to multiple federal government agencies. During a compliance planning meeting, the security team is asked which authorization framework the company must satisfy before federal agencies can procure and use the cloud service. Which compliance standard applies to this scenario?
A SOC analyst at a systems integrator is onboarding a new client that operates an information system on behalf of a U.S. federal executive branch agency. The client's contract requires them to categorize the system per FIPS 199, implement NIST SP 800-53 controls, and produce continuous monitoring reports for the agency's authorizing official. Which compliance framework is this client's program built around?
A SOC analyst at a European e-commerce company confirms that a breach exposed the names, addresses, and payment history of EU residents. The compliance officer asks how quickly the supervisory authority must be notified under the regulation that governs personal data of EU citizens. Which regulation applies, and what is the notification deadline?
A retail company runs its core inventory database in an on-premises data center for latency and control reasons, but during seasonal sales it dynamically extends the front-end web application into a public cloud provider to absorb traffic spikes. Sensitive processing stays internal while burst capacity is offloaded externally. Which cloud deployment model does this architecture best describe?
A security operations team is migrating a web application to a cloud provider. Under the Platform as a Service (PaaS) model they selected, the team wants to clarify which security responsibilities remain with them versus the cloud provider. Which task remains the responsibility of the customer's security operations team in a PaaS environment?
A SOC analyst receives an automated SIEM alert indicating multiple failed logins followed by a successful login on a domain controller. Before escalating or taking any containment action, the analyst reviews correlated logs, verifies the source IP reputation, and confirms whether the activity represents genuine malicious behavior. According to the incident response workflow, which phase is the analyst currently performing?
During an active malware outbreak, a SOC analyst confirms that three endpoints in the finance department are communicating with a known command-and-control server. The incident response team wants to stop the spread and preserve the infected systems for later forensic analysis without alerting the attacker prematurely. According to the incident response workflow, which action best represents the current phase the team should execute?
A SOC team has confirmed a malware infection on several endpoints. They have already isolated the affected hosts from the network and preserved forensic images. The team now needs to remove the malicious files, delete attacker-created accounts, and close the vulnerabilities the attacker exploited before restoring systems to production. According to the NIST incident response workflow, which phase are they entering?
A newly hired SOC manager reviews the organization's incident response program and discovers that analysts frequently waste time during active incidents locating contact information for legal counsel, deciding which forensic tools to use, and clarifying who has authority to disconnect production systems. The manager wants to address the root cause by strengthening a specific phase of the incident response workflow. Which phase should the manager focus on to resolve these recurring issues?
A SOC team has removed malware and closed the exploited vulnerability on several compromised web servers. Management now wants the servers returned to production. Before restoring them, the incident response lead insists on monitoring the systems in a controlled manner and confirming they behave normally. Which incident response phase does this activity represent, and what is its primary goal?
A multinational manufacturing company that also runs an e-commerce site is preparing for a formal certification that demonstrates it has a systematic, auditable Information Security Management System (ISMS) covering risk assessment, controls, and continual improvement across all business units. The board wants a globally recognized standard that is not tied to any single industry vertical. Which standard best fits this requirement?
A SOC manager reviews last quarter's incident response metrics. The team's average time from the moment an attacker first compromised a host until an analyst opened an investigation was 14 days, while the average time from investigation start to full remediation was only 3 hours. To reduce overall attacker dwell time, which metric should the manager prioritize improving and what does it indicate?
More 350-201 practice
Keep going with the other Cisco CCNP Cybersecurity CBRCOR (350-201) domains, or take a full timed mock exam.
← Back to 350-201 overview