Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 7 pages
Exam (elaborations)

SANS FOR508 || 100% Errorless Answers.

Document preview thumbnail
Preview 2 out of 7 pages

SANS FOR508 || 100% Errorless Answers.

Content preview

SANS FOR508 || 100% Errorless Answers.
Dwell Time correct answers The time an attacker has remained undetected within a network. An
important metric to track as it directly correlates with the ability of an attacker to accomplish
their objectives.

Breakout Time correct answers Time is takes an intruder to begin moving laterally once they
have an initial foothold in the network.

Main Threat Actors correct answers APT (Nation State Actors)
Organized Crime
Hacktivists

NIST correct answers US National Institute for Standards and Technology

Six-Step Incident Response Process correct answers 1: Preparation
2: Identification
3: Containment and Intelligence Development
4: Eradication and Remediation
5: Recovery
6: Follow-up

Six-Step - Preparation correct answers Incident response methodologies emphasize preparation-
not only establishing a response capability so the organization is ready to respond to incidents
but also preventing incidents by ensuring that systems, networks, and applications are
sufficiently secure.

Six-Step - Identificatoin correct answers Identification is triggered by a suspicious event. This
could be from a security appliance, a call to the help-desk, or the result of something discovered
via threat hunting. Event validation should occur and a decision made as to the severity of the
finding (not valid events lead to a full incident response). Once an incident response has begun,
this phase is used to better understand the findings and begin scoping the network for additional
compromise.

Six Step - Containment and Intelligence development correct answers In this phase, the goal is to
rapidly understand the adversary and begin crafting a containment strategy. Responders must
identify the initial vulnerability or exploit, how the attackers are maintaining persistence and
laterally moving in the network, and how command and control is being accomplished. in
conjunction with the previous scoping phase, responders will work to have a complete picture of
the attack and often implement changes to the environment to increase host and network
visibility. Threat intelligence is one of the key products of the IP team during this phase.

Six Step - Eradication and Remediation correct answers Arguably the most important phase of
the process, eradication aims to remove the threat and restore business operations to a normal
state. However, successful eradication cannot occur until the full scop of the intrusion is

, understood. A rush to this phase usually results in failure. Remediation plans are developed, and
recommendations are implemented in a planned and controlled manner. Ex. Include
-Block malicious IP addresses
-Blackhole malicious domain names
-Rebuild compromised systems
-Coordinate with cloud and service providers
-Enterprise-wide password changes
-Implementation validation

Recovery correct answers Recovery leads the enterprise back to day-to-day business. The
organization will have learned a lot during the incident investigation and will invariably have
many changes to implement to make the enterprise more defensible. Recovery plans are typically
divided into near-, mid-, and long-term goals, and near-term changes should start immediately.
The foal during this phase is to improve the overall security of the network and to detect and
prevent immediate reinfection. Some recovery models include
-Improve Enterprise Authentication Model
-Enhanced Network Visibility
-Establish comprehensive Patch Management Program
-Enforce Change Management Program
-Centralized Logging (SIM/SIEM)
-Enhance Password Portal
-Establish Security Awareness Training Program
-Network Redesign

Follow-Up correct answers Follow-Up is used to verify the incident has been mitigated, the
adversary has been removed, and additional countermeasures have been implemented correctly.
This step combines additional monitoring, network sweeps looking for new breaches, and
auditing the network 9penetration tests and compliance) to ensure new security mechanisms are
in place and functioning normally.

Problem with the Six-Step incident response process correct answers Few teams follow the
process as prescribed. Pressure leading to immediately move to the Eradication/Remediation
phase before true scoping and understanding of the incident occurs. Moving to eradication too
early removes the benefits and capabilities provided by cyber threat intelligence and intelligence-
driven incident response doctrine.

Whack-a-mole correct answers The organization blindly chases the attacker throughout the
network, making little overall progress.

What drives the immediate eradication/remediation call to arms? correct answers Fear of loosing
data
data deemed as too valuable, risk too high.

Intelligence Development correct answers -Tools, techniques, and procedures
-Understanding adversary intent
-Malware gathering

Document information

Uploaded on
February 3, 2026
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$11.39

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
SirAnton
3.7
(117)
Sold
788
Followers
438
Items
39621
Last sold
1 week ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions