Cisco

350-201 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 80-question bank.

Provider
Cisco
Question bank
80
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 350-201, a certification listed under Cisco. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Cisco. The certification credential is issued by Cisco, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. A threat actor behind a single computer exploited a cloud-based application by sending multiple concurrent API requests. These requests made the application unresponsive. Which solution protects the application from being overloaded and ensures more equitable application access across the end- user community?

    Choose one answer.

    Question illustration 1
    • Limit the number of API calls that a single client is allowed to make
    • Add restrictions on the edge router on how often a single client can access the API
    • Reduce the amount of data that can be fetched from the total pool of active clients that call the API
    • Increase the application cache of the total pool of active clients that call the API
  2. Question 2 · 1

    Refer to the exhibit. Which two steps mitigate attacks on the webserver from the Internet? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Create an ACL on the firewall to allow only TLS 1.3
    • Implement a reverse server in the DMZ network
    • Create an ACL on the firewall to allow only external connections
    • Move the webserver to the internal network
    • Move the webserver to the external network
  3. Question 3 · 1

    Refer to the exhibit. An engineer is investigating a case with suspicious usernames within the active directory. After the engineer investigates and cross-correlates events from other sources, it appears that the 2 users are privileged, and their creation date matches suspicious network traffic that was initiated from the internal network 2 days prior. Which type of compromise is occurring?

    Choose one answer.

    Question illustration 1
    • compromised insider
    • compromised root access
    • compromised database tables
    • compromised network
  4. Question 4 · 1

    Refer to the exhibit. An engineer received multiple reports from employees unable to log into systems with the error: The Group Policy Client service failed to logon `" Access is denied. Through further analysis, the engineer discovered several unexpected modifications to system settings. Which type of breach is occurring?

    Choose one answer.

    Question illustration 1
    • malware break
    • data theft
    • elevation of privileges
    • denial-of-service
  5. Question 5 · 1

    An engineer received an incident ticket of a malware outbreak and used antivirus and malware removal tools to eradicate the threat. The engineer notices that abnormal processes are still occurring in the system and determines that manual intervention is needed to clean the infected host and restore functionality. What is the next step the engineer should take to complete this playbook step?

    Choose one answer.

    • Scan the network to identify unknown assets and the asset owners.
    • Analyze the components of the infected hosts and associated business services.
    • Scan the host with updated signatures and remove temporary containment.
    • Analyze the impact of the malware and contain the artifacts.
  6. Question 6 · 1

    The SIEM tool informs a SOC team of a suspicious file. The team initializes the analysis with an automated sandbox tool, sets up a controlled laboratory to examine the malware specimen, and proceeds with behavioral analysis. What is the next step in the malware analysis process?

    Choose one answer.

    • Perform static and dynamic code analysis of the specimen.
    • Unpack the specimen and perform memory forensics.
    • Contain the subnet in which the suspicious file was found.
    • Document findings and clean-up the laboratory.
  7. Question 7 · 1

    DRAG DROP - Drag and drop the phases to evaluate the security posture of an asset from the left onto the activity that happens during the phases on the right. Select and Place:

    Match each destination with an option.

    Question illustration 1

    gathering information on a target for future use

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration

    probing the target to discover operating system details

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration

    confirming the existence of known vulnerabilities in the target system

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration

    using previously identified vulnerabilities to gain access to the target system

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration

    inserting backdoor access or covert channels to ensure access to the target system

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration

    erasing traces of actions in audit logs and registry entries

    • vulnerability assessment
    • persistence
    • exploit
    • cover tracks
    • reconnaissance
    • enumeration
  8. Question 8 · 1

    A logistic company must use an outdated application located in a private VLAN during the migration to new technologies. The IPS blocked and reported an unencrypted communication. Which tuning option should be applied to IPS?

    Choose one answer.

    • Allow list only authorized hosts to contact the application's IP at a specific port.
    • Allow list HTTP traffic through the corporate VLANS.
    • Allow list traffic to application's IP from the internal network at a specific port.
    • Allow list only authorized hosts to contact the application's VLAN.
  9. Question 9 · 1

    A company recently started accepting credit card payments in their local warehouses and is undergoing a PCI audit. Based on business requirements, the company needs to store sensitive authentication data for 45 days. How must data be stored for compliance?

    Choose one answer.

    • post-authorization by non-issuing entities if there is a documented business justification
    • by entities that issue the payment cards or that perform support issuing services
    • post-authorization by non-issuing entities if the data is encrypted and securely stored
    • by issuers and issuer processors if there is a legitimate reason
  10. Question 10 · 1

    An organization had an incident with the network availability during which devices unexpectedly malfunctioned. An engineer is investigating the incident and found that the memory pool buffer usage reached a peak before the malfunction. Which action should the engineer take to prevent this issue from reoccurring?

    Choose one answer.

    • Disable memory limit.
    • Disable CPU threshold trap toward the SNMP server.
    • Enable memory tracing notifications.
    • Enable memory threshold notifications.
  11. Question 11 · 1

    A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company-owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?

    Choose one answer.

    • Measure confidentiality level of downloaded documents.
    • Report to the incident response team.
    • Escalate to contractor's manager.
    • Communicate with the contractor to identify the motives.
  12. Question 12 · 1

    An engineer detects an intrusion event inside an organization's network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?

    Choose one answer.

    • Disconnect the affected server from the network.
    • Analyze the source.
    • Access the affected server to confirm compromised files are encrypted.
    • Determine the attack surface.
  13. Question 13 · 1

    According to GDPR, what should be done with data to ensure its confidentiality, integrity, and availability?

    Choose one answer.

    • Perform a vulnerability assessment
    • Conduct a data protection impact assessment
    • Conduct penetration testing
    • Perform awareness testing
  14. Question 14 · 1

    Which action should be taken when the HTTP response code 301 is received from a web application?

    Choose one answer.

    • Update the cached header metadata.
    • Confirm the resource's location.
    • Increase the allowed user limit.
    • Modify the session timeout setting.
  15. Question 15 · 1

    Employees receive an email from an executive within the organization that summarizes a recent security breach and requests that employees verify their credentials through a provided link. Several employees report the email as suspicious, and a security analyst is investigating the reports. Which two steps should the analyst take to begin this investigation? (Choose two.)

    Choose all answers that apply.

    • Evaluate the intrusion detection system alerts to determine the threat source and attack surface.
    • Communicate with employees to determine who opened the link and isolate the affected assets.
    • Examine the firewall and HIPS configuration to identify the exploited vulnerabilities and apply recommended mitigation.
    • Review the mail server and proxy logs to identify the impact of a potential breach.
    • Check the email header to identify the sender and analyze the link in an isolated environment.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free