SANS 515 EXAM FULLY SOLVED & UPDATED (LATEST VERSION VERIFIED FOR
ACCURACY) (QUESTIONS + ANSWERS) SOLVED 100% CORRECT!!
Question 1
In the "Sliding Scale of Cyber Security," where does the act of hunting for adversaries within a
network based on high-level hypotheses reside?
A) Architecture
B) Passive Defense
C) Active Defense
D) Intelligence
E) Offense
Correct Answer: C) Active Defense
Rationale: Active Defense involves the process of analysts monitoring for, responding to,
and learning from adversaries internal to the network. While Architecture and Passive
Defense provide the foundation, Active Defense is defined by human-led activities like
threat hunting and incident response.
Question 2
A "Supply Chain Backdoor" is a unique threat because it effectively combines which two phases
of the traditional intrusion cycle?
A) Research and C2
B) Tailored Capability and Impact
C) 1st Stage Delivery and Exploitation
D) Exfiltration and 2nd Stage Delivery
E) Visibility and Threat Detection
Correct Answer: C) Combines 1st Stage Delivery and Exploitation phases
Rationale: A supply chain attack bypasses standard perimeter defenses by embedding the
malicious capability directly into a trusted product. Because the user willingly "delivers"
the product to the system, the delivery and exploitation often occur simultaneously upon
installation.
Question 3
Which of the following host-based observables is specifically associated with the Stuxnet
malware's persistence and stealth mechanism?
A) Modification of the Master Boot Record
B) DLL Injection into Lsass.exe, winlogon.exe, and svchost.exe
C) Deletion of all .LOG files in the System32 folder
D) Encryption of the PLC ladder logic via AES-256
E) Disabling the Windows Firewall service
Correct Answer: B) DLL Injection: Lsass.exe, winlogon.exe, svchost.exe
Rationale: Stuxnet used advanced rootkit-like techniques, including injecting its malicious
code into critical system processes like Lsass and Winlogon, to hide its presence from the
operating system and security software.
, 2
Question 4
Which registry key value is a known indicator of a Stuxnet infection, often linked to a specific
date of historical significance?
A) 20100715
B) 19790509
C) 00000001
D) 88888888
E) mrxnet_config
Correct Answer: B) 19790509
Rationale: Stuxnet created a registry key named "mrxnet" with the value "19790509."
Analysts use this specific timestamp/value as a high-fidelity host-based indicator of
compromise (IOC).
Question 5
What is the "USB Jumping" limit programmed into the Stuxnet infection logic to prevent
uncontrolled spreading?
A) It deletes itself after 1 jump
B) It deletes itself after 3 jumps
C) It deletes itself after 10 jumps
D) It never deletes itself
E) It only jumps once per unique hardware ID
Correct Answer: B) Delete after 3 jumps
Rationale: To remain targeted and avoid excessive global noise that might lead to early
detection, Stuxnet was configured to limit its propagation via USB drives to three "jumps"
or unique infections via the temporary file WTR4141.tmp.
Question 6
According to the Active Cyber Defense Cycle (ACDC), what follows the "Threat Detection"
phase?
A) Visibility
B) Asset Identification
C) Incident Response
D) Threat Intelligence Consumption
E) Threat & Environment Manipulation
Correct Answer: C) Incident Response
Rationale: The ACDC follows a logical flow: Consumption of intelligence leads to increased
Visibility, which allows for Detection. Once a threat is detected, the next immediate action
is Response, followed by manipulating the environment to prevent future occurrences.
Question 7
The influence of General Depuy’s FM 100-5 on Active Defense focuses on which primary
, 3
concept?
A) Total destruction of the enemy's home network
B) Static defense using high-walls and DMZs
C) An active, fluid defense that seeks to identify and expel an adversary
D) Passive logging without human intervention
E) Diplomatic resolution of cyber conflicts
Correct Answer: C) The Army's FM 100-5
Rationale: General Depuy’s manual moved the US Army toward an "Active Defense"
posture—recognizing that static defenses are eventually breached and that a defender must
actively maneuver against an attacker within their own territory to be successful.
Question 8
Mao Zedong’s "Guiding Principles" for defense, adapted for cyber security, emphasize "No
provocation of the enemy." Why is this relevant to Active Defense?
A) It forbids the use of antivirus software
B) It suggests that defenders should not use "hack-back" or offensive measures
C) It requires that all firewalls be set to "Allow All"
D) It means the defender should never look at logs
E) It only applies to government-sponsored attacks
Correct Answer: B) No provocation of the enemy
Rationale: In the context of the SANS 515 model, Active Defense is about monitoring and
dispelling threats within your own network. Provocation or "hack-back" falls into the
Offense category, which carries significant legal and escalatory risks for private
organizations.
Question 9
In the context of the Intelligence Life Cycle, which phase involves converting raw data into a
format that can be used by human or machine analysts?
A) Planning and Direction
B) Collection
C) Process and Exploitation
D) Analysis and Production
E) Dissemination
Correct Answer: C) Process and Exploitation
Rationale: Processing involves translating raw data (like PCAP or binary files) into usable
information (like protocol dissections or strings). This "exploits" the data for the benefit of
the next phase: Analysis.
Question 10
"Field of View Bias" in intelligence collection is primarily a result of:
A) The analyst being tired
, 4
B) The specific Operational Environment and Intelligence Requirements
C) Using only open-source tools
D) The speed of the network connection
E) Encrypted traffic
Correct Answer: B) Operational Environment and Intelligence Requirements yield a "field
of view".
Rationale: An analyst's understanding is limited by where they are looking. If you only
collect logs from the DMZ (Operational Environment), you will be blind to "East-West"
movement within the ICS network. This limitation is known as Field of View Bias.
Question 11
How is a "Potential Threat" established using the Threat Equation?
A) Hostile Intent + Capability
B) Hostile Intent + Opportunity
C) Capability + Opportunity
D) Capability + Intent + Opportunity
E) Access + Malware
Correct Answer: C) Capability + Opportunity = potential
Rationale: A potential threat exists when an actor has the skills/tools (Capability) and the
access (Opportunity), even if their specific Intent toward your organization is not yet
confirmed. All three elements together create an "Impending" or "Active" threat.
Question 12
Which type of Threat Intelligence is intended for an audience of executives to help drive long-
term business and security investments?
A) Tactical
B) Operational
C) Forensic
D) Strategic
E) Procedural
Correct Answer: D) Strategic
Rationale: Strategic intelligence looks at broad trends, geopolitical risks, and high-level
attacker motivations. It is designed to inform decision-makers who manage budgets and
organizational risk posture.
Question 13
A security team is tracking the specific IP addresses and file hashes associated with a new
malware variant. This is an example of which type of intelligence?
A) Strategic
B) Tactical
C) Operational
ACCURACY) (QUESTIONS + ANSWERS) SOLVED 100% CORRECT!!
Question 1
In the "Sliding Scale of Cyber Security," where does the act of hunting for adversaries within a
network based on high-level hypotheses reside?
A) Architecture
B) Passive Defense
C) Active Defense
D) Intelligence
E) Offense
Correct Answer: C) Active Defense
Rationale: Active Defense involves the process of analysts monitoring for, responding to,
and learning from adversaries internal to the network. While Architecture and Passive
Defense provide the foundation, Active Defense is defined by human-led activities like
threat hunting and incident response.
Question 2
A "Supply Chain Backdoor" is a unique threat because it effectively combines which two phases
of the traditional intrusion cycle?
A) Research and C2
B) Tailored Capability and Impact
C) 1st Stage Delivery and Exploitation
D) Exfiltration and 2nd Stage Delivery
E) Visibility and Threat Detection
Correct Answer: C) Combines 1st Stage Delivery and Exploitation phases
Rationale: A supply chain attack bypasses standard perimeter defenses by embedding the
malicious capability directly into a trusted product. Because the user willingly "delivers"
the product to the system, the delivery and exploitation often occur simultaneously upon
installation.
Question 3
Which of the following host-based observables is specifically associated with the Stuxnet
malware's persistence and stealth mechanism?
A) Modification of the Master Boot Record
B) DLL Injection into Lsass.exe, winlogon.exe, and svchost.exe
C) Deletion of all .LOG files in the System32 folder
D) Encryption of the PLC ladder logic via AES-256
E) Disabling the Windows Firewall service
Correct Answer: B) DLL Injection: Lsass.exe, winlogon.exe, svchost.exe
Rationale: Stuxnet used advanced rootkit-like techniques, including injecting its malicious
code into critical system processes like Lsass and Winlogon, to hide its presence from the
operating system and security software.
, 2
Question 4
Which registry key value is a known indicator of a Stuxnet infection, often linked to a specific
date of historical significance?
A) 20100715
B) 19790509
C) 00000001
D) 88888888
E) mrxnet_config
Correct Answer: B) 19790509
Rationale: Stuxnet created a registry key named "mrxnet" with the value "19790509."
Analysts use this specific timestamp/value as a high-fidelity host-based indicator of
compromise (IOC).
Question 5
What is the "USB Jumping" limit programmed into the Stuxnet infection logic to prevent
uncontrolled spreading?
A) It deletes itself after 1 jump
B) It deletes itself after 3 jumps
C) It deletes itself after 10 jumps
D) It never deletes itself
E) It only jumps once per unique hardware ID
Correct Answer: B) Delete after 3 jumps
Rationale: To remain targeted and avoid excessive global noise that might lead to early
detection, Stuxnet was configured to limit its propagation via USB drives to three "jumps"
or unique infections via the temporary file WTR4141.tmp.
Question 6
According to the Active Cyber Defense Cycle (ACDC), what follows the "Threat Detection"
phase?
A) Visibility
B) Asset Identification
C) Incident Response
D) Threat Intelligence Consumption
E) Threat & Environment Manipulation
Correct Answer: C) Incident Response
Rationale: The ACDC follows a logical flow: Consumption of intelligence leads to increased
Visibility, which allows for Detection. Once a threat is detected, the next immediate action
is Response, followed by manipulating the environment to prevent future occurrences.
Question 7
The influence of General Depuy’s FM 100-5 on Active Defense focuses on which primary
, 3
concept?
A) Total destruction of the enemy's home network
B) Static defense using high-walls and DMZs
C) An active, fluid defense that seeks to identify and expel an adversary
D) Passive logging without human intervention
E) Diplomatic resolution of cyber conflicts
Correct Answer: C) The Army's FM 100-5
Rationale: General Depuy’s manual moved the US Army toward an "Active Defense"
posture—recognizing that static defenses are eventually breached and that a defender must
actively maneuver against an attacker within their own territory to be successful.
Question 8
Mao Zedong’s "Guiding Principles" for defense, adapted for cyber security, emphasize "No
provocation of the enemy." Why is this relevant to Active Defense?
A) It forbids the use of antivirus software
B) It suggests that defenders should not use "hack-back" or offensive measures
C) It requires that all firewalls be set to "Allow All"
D) It means the defender should never look at logs
E) It only applies to government-sponsored attacks
Correct Answer: B) No provocation of the enemy
Rationale: In the context of the SANS 515 model, Active Defense is about monitoring and
dispelling threats within your own network. Provocation or "hack-back" falls into the
Offense category, which carries significant legal and escalatory risks for private
organizations.
Question 9
In the context of the Intelligence Life Cycle, which phase involves converting raw data into a
format that can be used by human or machine analysts?
A) Planning and Direction
B) Collection
C) Process and Exploitation
D) Analysis and Production
E) Dissemination
Correct Answer: C) Process and Exploitation
Rationale: Processing involves translating raw data (like PCAP or binary files) into usable
information (like protocol dissections or strings). This "exploits" the data for the benefit of
the next phase: Analysis.
Question 10
"Field of View Bias" in intelligence collection is primarily a result of:
A) The analyst being tired
, 4
B) The specific Operational Environment and Intelligence Requirements
C) Using only open-source tools
D) The speed of the network connection
E) Encrypted traffic
Correct Answer: B) Operational Environment and Intelligence Requirements yield a "field
of view".
Rationale: An analyst's understanding is limited by where they are looking. If you only
collect logs from the DMZ (Operational Environment), you will be blind to "East-West"
movement within the ICS network. This limitation is known as Field of View Bias.
Question 11
How is a "Potential Threat" established using the Threat Equation?
A) Hostile Intent + Capability
B) Hostile Intent + Opportunity
C) Capability + Opportunity
D) Capability + Intent + Opportunity
E) Access + Malware
Correct Answer: C) Capability + Opportunity = potential
Rationale: A potential threat exists when an actor has the skills/tools (Capability) and the
access (Opportunity), even if their specific Intent toward your organization is not yet
confirmed. All three elements together create an "Impending" or "Active" threat.
Question 12
Which type of Threat Intelligence is intended for an audience of executives to help drive long-
term business and security investments?
A) Tactical
B) Operational
C) Forensic
D) Strategic
E) Procedural
Correct Answer: D) Strategic
Rationale: Strategic intelligence looks at broad trends, geopolitical risks, and high-level
attacker motivations. It is designed to inform decision-makers who manage budgets and
organizational risk posture.
Question 13
A security team is tracking the specific IP addresses and file hashes associated with a new
malware variant. This is an example of which type of intelligence?
A) Strategic
B) Tactical
C) Operational