SANS FOR508 COMPREHENSIVE
STUDY GUIDE 2026 FULL QUESTIONS
AND SOLUTIONS GRADED A+
◍ Dwell Time.
Answer: Time an attacker has remained undetected in the network.
◍ Breakout Time.
Answer: Time it takes an attacker to begin moving laterally once initiated
foothold in network.
◍ Incident Response Process (Six Steps).
Answer: 1. Preparation. 2. Identification/Scoping. 3.
Containment/Intelligence Development. 4. Eradication/Remediation. 5.
Recovery. 6. Lessons Learned/Threat Intel Consumption.
◍ Preparation - Step 1 of IR Process.
Answer: Establishing a response capability & preventing incidents by
ensuring systems, networks, & apps sufficiently secure.
◍ Identification/Scoping - Step 2 of IR Process.
Answer: Triggered by suspicious event. Event validation should occur,
decision made as to severity (not valid events lead to full IR response. One
IR begun, phase used to better understand findings & begin scoping network
for addt'l compromise.
◍ Containment/Intel Development - Step 3 of IR Process.
Answer: Goal to rapidly understand adversary begin crafting containment
strategy. Identify initial exploit, how attackers maintaining persistence &
laterally moving, how C2 being accomplished. Implement changes to
increase host/network visibility. Threat intel key part of phase.
, ◍ Eradication/Remediation - Step 4 of IR Process.
Answer: Arguably most important phase. Aim to remove threat, restore ops
to normal state. Ex. changes to environment: -Block malicious IP addresses;
blackhole malicious domain names; rebuild compromised systems;
coordinate w/cloud & service providers; Enterprise-wide password changes;
implementation validation
◍ Recovery - Step 5 of IR Process.
Answer: leads enterprise back to day-to-day business. Goal is to improve
overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility;
Establish Comprehensive Patch Mgmt Program; Centralized Logging
(SIEM/SIM); Enhance Password Portal; Establish Security Awareness
Training Program; Network Redesign
◍ Follow-Up - Step 6 of IR Process.
Answer: Verify incident mitigated, adversary removed, addt'l
countermeasures implemented correctly. Addt'l monitoring, network sweeps
looking for new breaches, auditing network (pen tests) to ensure new
security functioning normally
◍ Eradication w/o Proper Scoping/Containment.
Answer: Many orgs begin eradication too quickly. Stop gap measures
(pulling plug, blocking IP addresses, rebuilding systems, disabling
compromised accts) unlikely to lead to full eradication. "whack-a-mole"
when move too fast to eradication.
◍ Containment/Intel Development - Step 3 of IR Process.
Answer: Bulk of response time often spent here. Need for threat intel
collection can't be overstated. IOC development important at this phase.
W/enough intel, possible to predict attacker intent/future actions. When this
point reached, time to consider eradication phase.
◍ Compromised Host.
Answer: Any system the adversary has examined, utilized, or infected.
STUDY GUIDE 2026 FULL QUESTIONS
AND SOLUTIONS GRADED A+
◍ Dwell Time.
Answer: Time an attacker has remained undetected in the network.
◍ Breakout Time.
Answer: Time it takes an attacker to begin moving laterally once initiated
foothold in network.
◍ Incident Response Process (Six Steps).
Answer: 1. Preparation. 2. Identification/Scoping. 3.
Containment/Intelligence Development. 4. Eradication/Remediation. 5.
Recovery. 6. Lessons Learned/Threat Intel Consumption.
◍ Preparation - Step 1 of IR Process.
Answer: Establishing a response capability & preventing incidents by
ensuring systems, networks, & apps sufficiently secure.
◍ Identification/Scoping - Step 2 of IR Process.
Answer: Triggered by suspicious event. Event validation should occur,
decision made as to severity (not valid events lead to full IR response. One
IR begun, phase used to better understand findings & begin scoping network
for addt'l compromise.
◍ Containment/Intel Development - Step 3 of IR Process.
Answer: Goal to rapidly understand adversary begin crafting containment
strategy. Identify initial exploit, how attackers maintaining persistence &
laterally moving, how C2 being accomplished. Implement changes to
increase host/network visibility. Threat intel key part of phase.
, ◍ Eradication/Remediation - Step 4 of IR Process.
Answer: Arguably most important phase. Aim to remove threat, restore ops
to normal state. Ex. changes to environment: -Block malicious IP addresses;
blackhole malicious domain names; rebuild compromised systems;
coordinate w/cloud & service providers; Enterprise-wide password changes;
implementation validation
◍ Recovery - Step 5 of IR Process.
Answer: leads enterprise back to day-to-day business. Goal is to improve
overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility;
Establish Comprehensive Patch Mgmt Program; Centralized Logging
(SIEM/SIM); Enhance Password Portal; Establish Security Awareness
Training Program; Network Redesign
◍ Follow-Up - Step 6 of IR Process.
Answer: Verify incident mitigated, adversary removed, addt'l
countermeasures implemented correctly. Addt'l monitoring, network sweeps
looking for new breaches, auditing network (pen tests) to ensure new
security functioning normally
◍ Eradication w/o Proper Scoping/Containment.
Answer: Many orgs begin eradication too quickly. Stop gap measures
(pulling plug, blocking IP addresses, rebuilding systems, disabling
compromised accts) unlikely to lead to full eradication. "whack-a-mole"
when move too fast to eradication.
◍ Containment/Intel Development - Step 3 of IR Process.
Answer: Bulk of response time often spent here. Need for threat intel
collection can't be overstated. IOC development important at this phase.
W/enough intel, possible to predict attacker intent/future actions. When this
point reached, time to consider eradication phase.
◍ Compromised Host.
Answer: Any system the adversary has examined, utilized, or infected.