Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 8 pages
Exam (elaborations)

SANS FOR508 COMPREHENSIVE STUDY GUIDE 2026 FULL QUESTIONS AND SOLUTIONS GRADED A+

Document preview thumbnail
Preview 2 out of 8 pages

SANS FOR508 COMPREHENSIVE STUDY GUIDE 2026 FULL QUESTIONS AND SOLUTIONS GRADED A+

Content preview

SANS FOR508 COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+


● RegRipper. Answer: - automated HIVE parser - can parse the following HIVES: SAM,
SECURITY, SYSTEM, SOFTWARE, NTUSER.DAT - also used to parse restore point registry
files

● What is the first step of incident response?. Answer: - proper identification of ALL
systems compromised - may be systems compromised with inactive malware

● Preparation. Answer: - establish incident response capability - ensure systems, networks,
applications are sufficiently secure

● Identification. Answer: - the first step toward proper remediation

● Containment & Intel Development. Answer: - identify pivot point - learn lateral
movements of adversary - identify malware - use knowledge to engineer countermeasures
*Results in Threat Intelligence*

● Remediation. Answer: - actions required over a short period to mitigate current incident

● What are the six steps (in order) to ensure comprehensive remediation?. Answer: (1)
Block malicious IP addresses (2) Blackhole malicious domain names (3) Rebuild
compromised systems (4) Coordinate with cloud and service providers (5) Enterprise
password change (6) Verify all remediation activities

● Recovery. Answer: - move back to day-to-day business - implement long-term solutions -
prevent and detect future incidents

● Follow Up. Answer: - verify incident is mitigated (additional monitoring) - ensure adversary
is removed (network/host sweeps) - implement additional countermeasures (audit the
network)

● What are the six steps of Incident Response?. Answer: - Preparation - Identification -
Containment and Intel Development - Remediation - Recovery - Follow Up

● What is one of the key products of the Incident Response team during an incident?.
Answer: Threat intelligence

, ● Containment Options. Answer: - enable decoy data sets - bit mangling - adversary
network segmentation - full-scale host/network monitoring - kill switch

● Intelligence-driven Incident Response. Answer: - process used to identify actively new
compromised systems

● Initial Compromise. Answer: - not usually persistent

● Establish foothold/maintain presence. Answer: - maintained presence despite reboot

● Lateral Movement. Answer: - movement within the system - may use PSEXEC, Scheduled
Tasks, or WMI commands

● Data Collection. Answer: - generally leaves loud footprint on systems

● Data exfil. Answer: - may be detected by automated SIEM - easiest to detect

● Deep-dive Forensics. Answer: - memory analysis (all processes) - Timeline analysis (all
activity) - File system analysis (all)

● Enterprise Scanning. Answer: - memory analysis (specific processes) - Timeline analysis
(specific activity) - File system analysis (specific)

● 3 Steps of Remediation Event (Plan). Answer: - Posture - Execute - Implement controls

● 4 Remediation Event Goals. Answer: - deny access - restrict reaction - remove presence -
degrade survivability

● Actions to increase monitoring:. Answer: - full content packet captures on compromised
segments - full netflow data from all egress pts - retain and maintain DHCP, VPN, firewall, and
Web logs

● Critical Remediation Event Steps (8). Answer: - Disconnect environment from Internet -
Implement strict segmentation - Block IPs and domain names for C2 channels - Remove
infected systems - Remove all ID'd systems (those not active) - Restrict access to known
comp. accounts - Restrict access to domain admin accounts - Validate proper steps taken

● Risk. Answer: Comprised of vulnerability, impact, and threat

● Vulnerability. Answer: mutable and ephemeral

● Impact. Answer: immutable and changes are slow or non-existent

Document information

Uploaded on
March 7, 2026
Number of pages
8
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
32
Followers
1
Items
14355
Last sold
4 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions