with Detailed Rationales (Latest Update 2026) |100%
Guaranteed Pass!!!
1. Dwell Time
A) Time from initial compromise to remediation
B) Time an attacker has remained undetected within a network
C) Time from infection to detection
D) Time taken for lateral movement
Answer: B
Dwell time is a critical metric measuring how long an attacker operates unseen, directly correlating with their ability
to achieve objectives.
2. Breakout Time
A) Time to exfiltrate data
B) Time to establish persistence
C) Time it takes an intruder to begin moving laterally after initial foothold
D) Time to compromise the domain controller
Answer: C
Breakout time measures the window between initial compromise and the start of lateral movement, indicating
attacker speed.
3. What are the three main threat actors identified in FOR508?
A) Script Kiddies, Insiders, Competitors
B) APT (Nation State Actors), Organized Crime, Hacktivists
C) Ransomware Gangs, Terrorists, Spies
1|Page SUCCESS!!!
,D) Employees, Contractors, Vendors
Answer: B
FOR508 categorizes primary adversaries as nation-state APTs, organized crime syndicates, and hacktivists .
4. What is the first step of the incident response process?
A) Containment
B) Eradication
C) Preparation
D) Identification
Answer: C
Preparation establishes response capability and ensures systems are sufficiently secure before any incident occurs.
5. What are the six steps of the incident response process in order?
A) Preparation, Identification, Containment & Intel, Eradication & Remediation, Recovery, Follow-up
B) Detection, Analysis, Containment, Eradication, Recovery, Lessons Learned
C) Triage, Investigation, Containment, Remediation, Recovery, Reporting
D) Identification, Analysis, Containment, Eradication, Recovery, Follow-up
Answer: A
The SANS six-step IR process follows: Preparation → Identification → Containment/Intel Development →
Eradication/Remediation → Recovery → Follow-up.
6. What drives the immediate eradication/remediation "call to arms"?
A) Regulatory requirements
B) Fear of losing data deemed too valuable
C) Management pressure
D) Public disclosure requirements
2|Page SUCCESS!!!
,Answer: B
Fear of losing valuable data or accepting high risk drives premature eradication before proper scoping is complete.
7. What is the primary problem with the six-step incident response process in practice?
A) Teams lack proper tools
B) Few teams follow the process as prescribed; pressure leads to immediate eradication before scoping
C) The process is outdated
D) Teams focus too much on preparation
Answer: B
Teams often skip containment and intelligence development, rushing to eradication, which removes CTI benefits
and leads to failure.
8. Where is the bulk of response time spent during an incident?
A) Preparation phase
B) Identification phase
C) Containment/Intelligence Development phase
D) Recovery phase
Answer: C
The containment and intelligence development phase consumes most response time as responders rapidly
understand the adversary .
9. What is "Whack-a-Mole" in incident response?
A) A containment strategy
B) The organization blindly chasing the attacker throughout the network with little progress
C) A malware removal tool
D) A threat hunting technique
3|Page SUCCESS!!!
, Answer: B
Whack-a-mole describes ineffective response where teams react symptomatically without understanding full scope,
making little overall progress .
10. What is the goal of containment?
A) Remove all malware from the network
B) Degrade the capabilities of an adversary, denying them the opportunity to achieve their goals
C) Identify all compromised systems
D) Notify law enforcement
Answer: B
Containment degrades adversary capabilities, denying them the chance to achieve objectives while maintaining
visibility .
11. What is the primary goal of incident hunting?
A) Find all malware on the network
B) Reduce the dwell time of attackers
C) Comply with regulations
D) Replace incident response
Answer: B
Threat hunting actively seeks incidents to reduce attacker dwell time, preventing long-term undetected presence .
12. What's a key component to building a hunt team?
A) Expensive software
B) Having a cyber threat intelligence capability feeding directly to the hunt team
C) Large team size
D) External consultants
4|Page SUCCESS!!!