350-201 Dumps

350-201 Free Practice Test

Cisco 350-201: Performing CyberOps Using Core Security Technologies (CBRCOR)

QUESTION 16

An employee who often travels abroad logs in from a first-seen country during non-working hours. The SIEM tool generates an alert that the user is forwarding an increased amount of emails to an external mail domain and then logs out. The investigation concludes that the external domain belongs to a competitor. Which two behaviors triggered UEBA? (Choose two.)

Correct Answer: AB

QUESTION 17

An organization had a breach due to a phishing attack. An engineer leads a team through the recovery phase of the incident response process. Which action should be taken during this phase?

Correct Answer: C