• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 31 pages
Exam (elaborations)

SANS 515 Exam fully solved & updated (latest version verified for accuracy) (Questions + Answers) Solved 100% Correct!!

Document preview thumbnail
Preview 4 out of 31 pages

SANS 515 Exam fully solved & updated (latest version verified for accuracy) (Questions + Answers) Solved 100% Correct!!

Content preview

SANS 515 EXAM FULLY SOLVED & UPDATED (LATEST VERSION VERIFIED FOR
ACCURACY) (QUESTIONS + ANSWERS) SOLVED 100% CORRECT!!

Question 1
In the "Sliding Scale of Cyber Security," where does the act of hunting for adversaries within a
network based on high-level hypotheses reside?
A) Architecture
B) Passive Defense
C) Active Defense
D) Intelligence
E) Offense
Correct Answer: C) Active Defense
Rationale: Active Defense involves the process of analysts monitoring for, responding to,
and learning from adversaries internal to the network. While Architecture and Passive
Defense provide the foundation, Active Defense is defined by human-led activities like
threat hunting and incident response.

Question 2
A "Supply Chain Backdoor" is a unique threat because it effectively combines which two phases
of the traditional intrusion cycle?
A) Research and C2
B) Tailored Capability and Impact
C) 1st Stage Delivery and Exploitation
D) Exfiltration and 2nd Stage Delivery
E) Visibility and Threat Detection
Correct Answer: C) Combines 1st Stage Delivery and Exploitation phases
Rationale: A supply chain attack bypasses standard perimeter defenses by embedding the
malicious capability directly into a trusted product. Because the user willingly "delivers"
the product to the system, the delivery and exploitation often occur simultaneously upon
installation.

Question 3
Which of the following host-based observables is specifically associated with the Stuxnet
malware's persistence and stealth mechanism?
A) Modification of the Master Boot Record
B) DLL Injection into Lsass.exe, winlogon.exe, and svchost.exe
C) Deletion of all .LOG files in the System32 folder
D) Encryption of the PLC ladder logic via AES-256
E) Disabling the Windows Firewall service
Correct Answer: B) DLL Injection: Lsass.exe, winlogon.exe, svchost.exe
Rationale: Stuxnet used advanced rootkit-like techniques, including injecting its malicious
code into critical system processes like Lsass and Winlogon, to hide its presence from the
operating system and security software.

, 2



Question 4
Which registry key value is a known indicator of a Stuxnet infection, often linked to a specific
date of historical significance?
A) 20100715
B) 19790509
C) 00000001
D) 88888888
E) mrxnet_config
Correct Answer: B) 19790509
Rationale: Stuxnet created a registry key named "mrxnet" with the value "19790509."
Analysts use this specific timestamp/value as a high-fidelity host-based indicator of
compromise (IOC).
Question 5
What is the "USB Jumping" limit programmed into the Stuxnet infection logic to prevent
uncontrolled spreading?
A) It deletes itself after 1 jump
B) It deletes itself after 3 jumps
C) It deletes itself after 10 jumps
D) It never deletes itself
E) It only jumps once per unique hardware ID
Correct Answer: B) Delete after 3 jumps
Rationale: To remain targeted and avoid excessive global noise that might lead to early
detection, Stuxnet was configured to limit its propagation via USB drives to three "jumps"
or unique infections via the temporary file WTR4141.tmp.

Question 6
According to the Active Cyber Defense Cycle (ACDC), what follows the "Threat Detection"
phase?
A) Visibility
B) Asset Identification
C) Incident Response
D) Threat Intelligence Consumption
E) Threat & Environment Manipulation
Correct Answer: C) Incident Response
Rationale: The ACDC follows a logical flow: Consumption of intelligence leads to increased
Visibility, which allows for Detection. Once a threat is detected, the next immediate action
is Response, followed by manipulating the environment to prevent future occurrences.
Question 7
The influence of General Depuy’s FM 100-5 on Active Defense focuses on which primary

, 3



concept?
A) Total destruction of the enemy's home network
B) Static defense using high-walls and DMZs
C) An active, fluid defense that seeks to identify and expel an adversary
D) Passive logging without human intervention
E) Diplomatic resolution of cyber conflicts
Correct Answer: C) The Army's FM 100-5
Rationale: General Depuy’s manual moved the US Army toward an "Active Defense"
posture—recognizing that static defenses are eventually breached and that a defender must
actively maneuver against an attacker within their own territory to be successful.

Question 8
Mao Zedong’s "Guiding Principles" for defense, adapted for cyber security, emphasize "No
provocation of the enemy." Why is this relevant to Active Defense?
A) It forbids the use of antivirus software
B) It suggests that defenders should not use "hack-back" or offensive measures
C) It requires that all firewalls be set to "Allow All"
D) It means the defender should never look at logs
E) It only applies to government-sponsored attacks
Correct Answer: B) No provocation of the enemy
Rationale: In the context of the SANS 515 model, Active Defense is about monitoring and
dispelling threats within your own network. Provocation or "hack-back" falls into the
Offense category, which carries significant legal and escalatory risks for private
organizations.

Question 9
In the context of the Intelligence Life Cycle, which phase involves converting raw data into a
format that can be used by human or machine analysts?
A) Planning and Direction
B) Collection
C) Process and Exploitation
D) Analysis and Production
E) Dissemination
Correct Answer: C) Process and Exploitation
Rationale: Processing involves translating raw data (like PCAP or binary files) into usable
information (like protocol dissections or strings). This "exploits" the data for the benefit of
the next phase: Analysis.

Question 10
"Field of View Bias" in intelligence collection is primarily a result of:
A) The analyst being tired

, 4



B) The specific Operational Environment and Intelligence Requirements
C) Using only open-source tools
D) The speed of the network connection
E) Encrypted traffic
Correct Answer: B) Operational Environment and Intelligence Requirements yield a "field
of view".
Rationale: An analyst's understanding is limited by where they are looking. If you only
collect logs from the DMZ (Operational Environment), you will be blind to "East-West"
movement within the ICS network. This limitation is known as Field of View Bias.

Question 11
How is a "Potential Threat" established using the Threat Equation?
A) Hostile Intent + Capability
B) Hostile Intent + Opportunity
C) Capability + Opportunity
D) Capability + Intent + Opportunity
E) Access + Malware
Correct Answer: C) Capability + Opportunity = potential
Rationale: A potential threat exists when an actor has the skills/tools (Capability) and the
access (Opportunity), even if their specific Intent toward your organization is not yet
confirmed. All three elements together create an "Impending" or "Active" threat.

Question 12
Which type of Threat Intelligence is intended for an audience of executives to help drive long-
term business and security investments?
A) Tactical
B) Operational
C) Forensic
D) Strategic
E) Procedural
Correct Answer: D) Strategic
Rationale: Strategic intelligence looks at broad trends, geopolitical risks, and high-level
attacker motivations. It is designed to inform decision-makers who manage budgets and
organizational risk posture.
Question 13
A security team is tracking the specific IP addresses and file hashes associated with a new
malware variant. This is an example of which type of intelligence?
A) Strategic
B) Tactical
C) Operational

Document information

Uploaded on
April 23, 2026
Number of pages
31
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Braintrust
5.0
(274)
Sold
1307
Followers
5
Items
366
Last sold
4 days ago

Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions