Cohesity COH350 Certification Exam Sample Questions and Answers

Security Specialist Dumps, COH350 Dumps, Cohesity Security Specialist PDF, COH350 PDF, Security Specialist VCE, Cohesity Security Specialist Questions PDF, Cohesity Exam VCE, Cohesity COH350 VCE, Security Specialist Cheat SheetBefore you write the Cohesity Security Specialist (COH350) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Cohesity Certified Security Specialist sample questions and demo exam help you in removing these doubts and prepare you to take the test.

The best approach to pass your Cohesity COH350 exam is to challenge and improve your knowledge. To test your learning and identify improvement areas with actual exam format, we suggest you practice with Premium Cohesity COH350 Certification Practice Exam. The practice test is one of the most important elements of your Cohesity Security Specialist exam study strategy to discover your strengths and weaknesses, to improve your time management skills and to get an idea of the score you can expect.

Cohesity COH350 (Security Specialist) Sample Questions:

01. You are drafting the recovery runbook for a destructive-malware scenario. One of its stated goals is that the investigation must remain possible while service is being restored.
Which two runbook steps serve that goal?
(Choose two.)
a) Rebuild the affected systems from a clean image right away so that the estate is known good.
b) Preserve the recovery points from the affected period rather than treating them as suspect material.
c) Bring the workloads back on alternate hosts and leave the affected systems isolated and powered off.
d) Re-register the affected sources so that protection resumes as soon as the systems are back.
 
02. During recovery from an intrusion, the credentials used by the platform's administrators are suspected to be in the attacker's hands. An engineer proposes running the restores now with the existing service account and dealing with credentials once service is back.
How should the runbook direct this?
a) Disable the service account and carry out the restores with the admin account until the incident is closed.
b) Rotate the affected credentials first, so the recovery is not driven by secrets the attacker may still hold.
c) Proceed with the restores as proposed, then rotate every credential once the workloads are serving users.
d) Continue with the existing account, relying on multi-factor authentication to stop anyone else from using it.
 
03. Your plan holds two additional copies: one replicated to a second cluster that your same administrators manage with the same credentials, and one archived to an External Target under a policy with DataLock enabled. A tabletop exercise assumes an attacker holding cluster administrator credentials.
Which assessment of the two copies is correct?
a) Both copies survive the exercise, because a copy held on a second cluster is beyond the reach of the original cluster's credentials.
b) Neither copy survives, because an attacker holding administrator credentials can remove the archived copy along with the local ones.
c) The replicated copy remains modifiable by those administrators, while the archived copy is protected from modification by cluster users.
d) The replicated copy is the stronger of the two, because a second cluster supplies both separation and its own administrative identities.
 
04. A file server has been compromised. Forensics needs the affected system left exactly as it stands, and the business needs the file data available to its users again.
Which recovery choice serves both needs?
a) Postpone the restore until the forensic examination of the affected server has been completed.
b) Restore the data in place, having first exported the server's logs for the investigators to work from.
c) Restore the data in place onto the affected server once the malicious process has been stopped.
d) Recover the data to an alternate location and leave the affected server untouched for the investigation.
 
05. Following a ransomware event, one candidate recovery point predates the earliest evidence of compromise. The business is pressing for the workload back today, and the security lead insists that nothing be returned to production unverified.
Which recovery sequence satisfies both positions?
a) Restore into production and hold the restored systems behind a tightened allowlist until the scanning work finishes.
b) Recover the candidate copy into the Clean Room, confirm it is free of the threat, and then return it to production.
c) Run an instant mass restore of the workload into production, then scan the recovered systems for the threat.
d) Extend retention on the surviving copies and postpone any recovery until the forensic report has been issued.
 
06. DataLock on a Protection Policy can be toggled by a holder of the data security role. Your risk committee rules that no single individual should be able to weaken immutability on the policies covering regulated records.
Which control satisfies that ruling?
a) Place the change behind a Quorum group so it requires approval from additional authorized users.
b) Withdraw the data security role from everyone and have the admin account make the change when it is needed.
c) Replace the data security role with a custom role restricted to the sources holding the regulated records.
d) Configure alert notification so the committee is told whenever DataLock is changed on those policies.
 
07. Incident responders ask for assurance that the record of administrative actions will still be available to them if the cluster itself is compromised or wiped.
Which measure provides that assurance?
a) Schedule a report from the custom reporting database summarizing administrative activity.
b) Configure alert notification so responders receive a message for each privileged action.
c) Forward the log stream to a remote syslog destination held outside the cluster.
d) Enable audit logging on the cluster and retain the entries for the full investigation window.
 
08. A readiness review lists three controls that are already in place: DataLock on the archival policy, alert notification on unusual change activity in protected data, and a Clean Room in which recovered data is examined.
Which statement classifies these three correctly?
a) DataLock prevents alteration, the Clean Room provides detection, and alert notification records the event for later review.
b) DataLock prevents alteration, alert notification provides detection, and the Clean Room supports validated recovery.
c) All three are recovery controls, because each of them is exercised only after an incident has been declared.
d) DataLock detects tampering, alert notification prevents it, and the Clean Room provides the recovery path.
 
09. Your network team has placed the cluster's administrative interfaces on a management network reachable only from the security operations subnet, while backup data moves over a separate network. A colleague concludes that the cluster's default SSL certificate can now be left in place.
How should you assess that conclusion?
a) The conclusion fails, because a default certificate still lets a man-in-the-middle on that network capture cluster credentials.
b) The conclusion holds for administration, though the certificate should still be replaced to protect the backup data path against interception.
c) The conclusion fails, because certificate replacement is what permits the management interfaces to be reached from a restricted subnet.
d) The conclusion holds, because administrative sessions confined to a restricted management network cannot be intercepted in transit.
 
10. Following a ransomware event, your team intends to bring a candidate copy into a Clean Room and validate it there before anything is restored to production.
Which condition must hold for the copy the team selects?
a) It carries DataLock, and that establishes its contents are free of any changes the attacker made.
b) It has already been restored into production, so that its integrity can be checked against the live systems it came from and their current state.
c) It is the most recent copy available, so that the smallest possible amount of work is lost when production is rebuilt.
d) It predates the earliest evidence of compromise, and it is validated inside the isolated environment before any production restore.

Solutions:

Question: 01

Answer: b, c

Question: 02

Answer: b

Question: 03

Answer: c

Question: 04

Answer: d

Question: 05

Answer: b

Question: 06

Answer: a

Question: 07

Answer: c

Question: 08

Answer: b

Question: 09

Answer: a

Question: 10

Answer: d

Note: If you find any error in these Cohesity Security Specialist sample questions, you can update us by write an email on feedback@nwexam.com.

Rating: 4.8 / 5 (110 votes)