Cisco CCNP Cybersecurity CBRCOR (350-201) · Domain 3 · 30% of exam

Processes

Drill 20 practice questions focused entirely on Processes for the Cisco 350-201 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A SOC analyst receives an alert that a large volume of files from the company's SaaS-based file-sharing platform was downloaded and then shared externally by a single user account over a two-hour window. The security team suspects data exfiltration. Which action should the analyst take FIRST to investigate this potential cloud data loss event?

Reviewed for accuracy · Report an issue
Question 2 of 20

During a data-loss investigation, an analyst reviews CASB logs and finds that a departing employee shared a folder from the corporate cloud storage tenant to a personal Gmail address, then downloaded 4 GB of files to an unmanaged device over the following two days. The security team wants to characterize the exfiltration modality to scope the investigation correctly. Which modality of data loss best describes this event?

Reviewed for accuracy · Report an issue
Question 3 of 20

A vulnerability analyst is scoring a newly disclosed flaw in an internet-facing web application. The vulnerability can be exploited by an unauthenticated remote attacker sending a crafted HTTP request, requires no user interaction, and results in full compromise of confidentiality, integrity, and availability of the application. Which CVSS v3.1 Base metric assignment most accurately reflects that the attack can be launched from anywhere on the internet without local or adjacent access?

Reviewed for accuracy · Report an issue
Question 4 of 20

A SOC analyst responds to a suspected intrusion on a Windows desktop that is still powered on and connected to the network. Management wants the investigation to preserve the maximum amount of forensic evidence. According to the order of volatility, which data should the analyst collect FIRST during the endpoint investigation?

Reviewed for accuracy · Report an issue
Question 5 of 20

A financial analyst's laptop triggered a DLP alert indicating that a spreadsheet tagged as confidential was copied to an external device. As the SOC analyst assigned to investigate this potential endpoint data loss, which action should you take FIRST to confirm the exfiltration and preserve evidence?

Reviewed for accuracy · Report an issue
Question 6 of 20

During an investigation, a SOC analyst reviews EDR telemetry from a compromised workstation. The analyst notes two distinct findings: (1) a specific SHA-256 hash matching a file quarantined on the host, and (2) a PowerShell process spawning from a Word document and immediately establishing an encoded outbound connection while attempting to disable logging. The analyst must classify these findings correctly to inform detection strategy. How should the analyst categorize the two findings?

Reviewed for accuracy · Report an issue
Question 7 of 20

A SOC analyst receives an alert that a networked smart thermostat (an embedded Linux IoT device) in a corporate facility is beaconing to an unfamiliar external IP over an encrypted channel. The device has no traditional EDR agent, limited storage, and a read-only firmware partition. The analyst must begin investigating the potential endpoint intrusion. Given the platform constraints, what is the MOST appropriate first investigative step?

Reviewed for accuracy · Report an issue
Question 8 of 20

A SOC analyst is dispatched to investigate a corporate laptop suspected of running fileless malware. The user reports the machine is still powered on and connected to the network, and threat intel indicates the malware injects into legitimate processes and leaves minimal disk artifacts. To preserve the most relevant evidence for this type of intrusion, what should the analyst prioritize first?

Reviewed for accuracy · Report an issue
Question 9 of 20

During dynamic analysis of a suspicious executable, an analyst notices that the sample runs briefly, performs no observable network or file activity, and then exits cleanly in the sandbox. However, endpoint telemetry from an infected production host shows extensive persistence and C2 traffic from the same binary. Which conclusion best explains this discrepancy, and what is the appropriate next step?

Reviewed for accuracy · Report an issue
Question 10 of 20

During malware analysis, an analyst detonates a suspicious executable in a sandbox. The behavioral report shows the sample creates a scheduled task, writes to the Run registry key, injects code into explorer.exe, and beacons to an external domain every 60 seconds. Before writing the final report, the analyst wants to classify the sample's primary threat behavior to prioritize the response. Which observed behavior most directly indicates the sample's persistence mechanism?

Reviewed for accuracy · Report an issue
Question 11 of 20

A malware analyst has already completed static triage (hashing, string extraction) and dynamic execution in a sandbox for a suspicious binary. The behavioral report shows the sample connects to a C2 server, but the exact command structure and encryption routine used for exfiltration remain unclear because the traffic is encoded. The analyst needs to fully understand the algorithm the malware uses to encode its C2 payloads. Which analysis technique should be performed next to obtain this level of detail?

Reviewed for accuracy · Report an issue
Question 12 of 20

A SOC analyst receives 300 suspicious email attachments per day and cannot manually examine each one. The team wants to rapidly filter samples so that only unknown or ambiguous ones are escalated for deeper analysis. According to the standard malware analysis process, which stage should be applied FIRST to triage this high volume of samples with minimal analyst effort?

Reviewed for accuracy · Report an issue
Question 13 of 20

A malware analyst has completed static analysis of a suspicious executable and is preparing to observe its runtime behavior in a dedicated analysis lab. Before detonating the sample, the analyst wants to capture the malware's command-and-control callback attempts and dropped payloads without risking the corporate network or tipping off the attacker's infrastructure. Which configuration should the analyst apply to the dynamic analysis environment before executing the sample?

Reviewed for accuracy · Report an issue
Question 14 of 20

During analysis of a suspicious Windows executable, an analyst runs a static examination and finds almost no readable strings, high section entropy, and an unusually small import table containing only LoadLibrary and GetProcAddress. Dynamic execution in the sandbox shows the process allocating a large region of memory marked RWX and then jumping into it. Which conclusion and next step best fit these findings?

Reviewed for accuracy · Report an issue
Question 15 of 20

A SOC analyst receives a suspicious executable and must prepare it for transfer to the malware analysis team and for documentation in the case ticket. Before storing and sharing the live sample among analysts, which handling practice should the analyst apply first to prevent accidental execution while preserving the file for analysis?

Reviewed for accuracy · Report an issue
Question 16 of 20

A SOC analyst receives a suspicious executable flagged by an endpoint agent and needs to prepare a lab environment to perform dynamic analysis. Before detonating the sample, the analyst wants to observe the malware's true network behavior (such as C2 beaconing and DNS lookups) without allowing it to reach or infect production systems or the live internet. Which lab configuration BEST supports safe and effective dynamic analysis of this network behavior?

Reviewed for accuracy · Report an issue
Question 17 of 20

A malware analyst receives a suspicious executable recovered from an infected workstation. Before executing the sample, the analyst wants to safely extract metadata such as embedded strings, PE header details, imported API functions, and any packer signatures, without allowing the code to run. Which phase of the malware analysis process should the analyst perform FIRST, and why is it sequenced this way?

Reviewed for accuracy · Report an issue
Question 18 of 20

A malware analyst receives a suspicious Windows executable flagged by an endpoint agent. Before detonating the sample, the analyst wants to gather quick, low-risk intelligence such as embedded URLs, potential registry keys, and hardcoded IP addresses without executing the file. Which technique should the analyst use at this stage of the malware analysis process?

Reviewed for accuracy · Report an issue
Question 19 of 20

A SOC analyst receives a suspicious binary flagged by an endpoint agent. Before investing hours in dynamic and manual code analysis, the analyst wants to quickly determine whether the sample matches a previously catalogued threat family so the team can reuse existing IOCs and response procedures. Which action represents the correct FIRST step in the malware analysis process to achieve this goal efficiently?

Reviewed for accuracy · Report an issue
Question 20 of 20

A SOC analyst receives an alert that a corporate-managed Android smartphone belonging to an executive has begun beaconing to an unfamiliar external IP address every few minutes. The device is enrolled in the organization's Mobile Device Management (MDM) platform and contains sensitive email and files. The executive is currently traveling internationally and is using the device. What is the BEST first investigative step to take?

Reviewed for accuracy · Report an issue

More 350-201 practice

Keep going with the other Cisco CCNP Cybersecurity CBRCOR (350-201) domains, or take a full timed mock exam.

← Back to 350-201 overview