SANS FOR 508 ExAm PRACTICE QuESTIONS,muLTICHOICE
ANSWERS WITH RATIONALES <uPDATED VERSION OF
2026/2027>
1. what does "dwell time" measure in incident response?
a) the time an attacker takes to break into the network
b) the time an attacker remains undetected within a network
c) the time to contain an incident
d) the time to recover from an attack
correct answer: b
rationale: according to the text, dwell time is the time an attacker has remained undetected within a
network, directly correlating with their ability to accomplish objectives.
2. what is "breakout time"?
a) time to detect an intrusion
b) time it takes an intruder to begin moving laterally once they have an initial foothold
c) time to eradicate malware
d) time to notify management
correct answer: b
rationale: the text defines breakout time as the time an intruder takes to begin moving laterally after
gaining an initial foothold.
3. which of the following is listed as a main threat actor?
a) disgruntled employees only
b) apt (nation state actors), organized crime, hacktivists
c) script kiddies only
d) competitors only
correct answer: b
rationale: the text explicitly lists apt (nation state actors), organized crime, and hacktivists as main
threat actors.
4. what does nist stand for?
,a) national institute for security technology
b) national institute for standards and technology
c) north american institute for security testing
d) network incident security team
correct answer: b
rationale: the text states nist = us national institute for standards and technology.
5. how many steps are in the sixstep incident response process?
a) four
b) five
c) six
d) seven
correct answer: c
rationale: the text lists a sixstep incident response process: preparation, identification, containment
and intelligence development, eradication and remediation, recovery, followup.
6. which step emphasizes preventing incidents by ensuring systems are sufficiently secure?
a) identification
b) containment
c) preparation
d) recovery
correct answer: c
rationale: the text states preparation includes not only response capability but also preventing
incidents by securing systems, networks, and applications.
7. what triggers the identification step?
a) a scheduled audit
b) a suspicious event from a security appliance, helpdesk call, or threat hunting
c) an annual budget review
d) a management request
correct answer: b
rationale: according to the text, identification is triggered by a suspicious event, such as from a
security appliance, helpdesk call, or threat hunting.
, 8. during which phase do responders identify the initial vulnerability and how attackers maintain
persistence?
a) preparation
b) identification
c) containment and intelligence development
d) followup
correct answer: c
rationale: the text states that in containment and intelligence development, responders identify the
initial vulnerability, persistence, lateral movement, and c2.
9. what is a key product of the incident response team during the containment and intelligence
development phase?
a) financial audit
b) threat intelligence
c) employee training schedule
d) marketing plan
correct answer: b
rationale: the text says threat intelligence is one of the key products of the ir team during this phase.
10. which phase is described as arguably the most important?
a) preparation
b) identification
c) eradication and remediation
d) followup
correct answer: c
rationale: the text states eradication and remediation is "arguably the most important phase of the
process."
11. what is the risk of rushing to the eradication and remediation phase?
a) faster recovery
b) lower costs
c) failure because full scope of intrusion is not understood
d) improved employee morale
ANSWERS WITH RATIONALES <uPDATED VERSION OF
2026/2027>
1. what does "dwell time" measure in incident response?
a) the time an attacker takes to break into the network
b) the time an attacker remains undetected within a network
c) the time to contain an incident
d) the time to recover from an attack
correct answer: b
rationale: according to the text, dwell time is the time an attacker has remained undetected within a
network, directly correlating with their ability to accomplish objectives.
2. what is "breakout time"?
a) time to detect an intrusion
b) time it takes an intruder to begin moving laterally once they have an initial foothold
c) time to eradicate malware
d) time to notify management
correct answer: b
rationale: the text defines breakout time as the time an intruder takes to begin moving laterally after
gaining an initial foothold.
3. which of the following is listed as a main threat actor?
a) disgruntled employees only
b) apt (nation state actors), organized crime, hacktivists
c) script kiddies only
d) competitors only
correct answer: b
rationale: the text explicitly lists apt (nation state actors), organized crime, and hacktivists as main
threat actors.
4. what does nist stand for?
,a) national institute for security technology
b) national institute for standards and technology
c) north american institute for security testing
d) network incident security team
correct answer: b
rationale: the text states nist = us national institute for standards and technology.
5. how many steps are in the sixstep incident response process?
a) four
b) five
c) six
d) seven
correct answer: c
rationale: the text lists a sixstep incident response process: preparation, identification, containment
and intelligence development, eradication and remediation, recovery, followup.
6. which step emphasizes preventing incidents by ensuring systems are sufficiently secure?
a) identification
b) containment
c) preparation
d) recovery
correct answer: c
rationale: the text states preparation includes not only response capability but also preventing
incidents by securing systems, networks, and applications.
7. what triggers the identification step?
a) a scheduled audit
b) a suspicious event from a security appliance, helpdesk call, or threat hunting
c) an annual budget review
d) a management request
correct answer: b
rationale: according to the text, identification is triggered by a suspicious event, such as from a
security appliance, helpdesk call, or threat hunting.
, 8. during which phase do responders identify the initial vulnerability and how attackers maintain
persistence?
a) preparation
b) identification
c) containment and intelligence development
d) followup
correct answer: c
rationale: the text states that in containment and intelligence development, responders identify the
initial vulnerability, persistence, lateral movement, and c2.
9. what is a key product of the incident response team during the containment and intelligence
development phase?
a) financial audit
b) threat intelligence
c) employee training schedule
d) marketing plan
correct answer: b
rationale: the text says threat intelligence is one of the key products of the ir team during this phase.
10. which phase is described as arguably the most important?
a) preparation
b) identification
c) eradication and remediation
d) followup
correct answer: c
rationale: the text states eradication and remediation is "arguably the most important phase of the
process."
11. what is the risk of rushing to the eradication and remediation phase?
a) faster recovery
b) lower costs
c) failure because full scope of intrusion is not understood
d) improved employee morale