Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 3 fuera de 19 páginas
Examen

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Document preview thumbnail
Vista previa 3 fuera de 19 páginas

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Vista previa del contenido

SANS FOR508 PRACTICE
EXAMINATION 2026 QUESTIONS
WITH ANSWERS GRADED A+

◍ Dwell Time.
Answer: The time an attacker has remained undetected within a network. An
important metric to track as it directly correlates with the ability of an
attacker to accomplish their objectives.
◍ RegRipper.
Answer: - automated HIVE parser- can parse the following HIVES: SAM,
SECURITY, SYSTEM, SOFTWARE, NTUSER.DAT- also used to parse
restore point registry files
◍ Breakout Time.
Answer: Time is takes an intruder to begin moving laterally once they have
an initial foothold in the network.
◍ What is the first step of incident response?.
Answer: - proper identification of ALL systems compromised- may be
systems compromised with inactive malware
◍ Preparation.
Answer: - establish incident response capability- ensure systems, networks,
applications are sufficiently secure
◍ Identification.
Answer: - the first step toward proper remediation
◍ Containment & Intel Development.
Answer: - identify pivot point - learn lateral movements of adversary-
identify malware- use knowledge to engineer countermeasures *Results in

, Threat Intelligence*
◍ Remediation.
Answer: - actions required over a short period to mitigate current incident
◍ What are the six steps (in order) to ensure comprehensive remediation?.
Answer: (1) Block malicious IP addresses(2) Blackhole malicious domain
names(3) Rebuild compromised systems(4) Coordinate with cloud and
service providers(5) Enterprise password change(6) Verify all remediation
activities
◍ Recovery.
Answer: - move back to day-to-day business- implement long-term
solutions- prevent and detect future incidents
◍ Main Threat Actors.
Answer: APT (Nation State Actors)Organized CrimeHacktivists
◍ NIST.
Answer: US National Institute for Standards and Technology
◍ Follow Up.
Answer: - verify incident is mitigated (additional monitoring)- ensure
adversary is removed (network/host sweeps)- implement additional
countermeasures (audit the network)
◍ Six-Step Incident Response Process.
Answer: 1: Preparation2: Identification3: Containment and Intelligence
Development4: Eradication and Remediation5: Recovery6: Follow-up
◍ Six-Step - Preparation.
Answer: Incident response methodologies emphasize preparation-not only
establishing a response capability so the organization is ready to respond to
incidents but also preventing incidents by ensuring that systems, networks,
and applications are sufficiently secure.
◍ What are the six steps of Incident Response?.
Answer: - Preparation- Identification- Containment and Intel Development-

, Remediation- Recovery- Follow Up
◍ What is one of the key products of the Incident Response team during an
incident?.
Answer: Threat intelligence
◍ Containment Options.
Answer: - enable decoy data sets- bit mangling- adversary network
segmentation- full-scale host/network monitoring- kill switch
◍ Six-Step - Identificatoin.
Answer: Identification is triggered by a suspicious event. This could be from
a security appliance, a call to the help-desk, or the result of something
discovered via threat hunting. Event validation should occur and a decision
made as to the severity of the finding (not valid events lead to a full incident
response). Once an incident response has begun, this phase is used to better
understand the findings and begin scoping the network for additional
compromise.
◍ Intelligence-driven Incident Response.
Answer: - process used to identify actively new compromised systems
◍ Initial Compromise.
Answer: - not usually persistent
◍ Establish foothold/maintain presence.
Answer: - maintained presence despite reboot
◍ Six Step - Containment and Intelligence development.
Answer: In this phase, the goal is to rapidly understand the adversary and
begin crafting a containment strategy. Responders must identify the initial
vulnerability or exploit, how the attackers are maintaining persistence and
laterally moving in the network, and how command and control is being
accomplished. in conjunction with the previous scoping phase, responders
will work to have a complete picture of the attack and often implement
changes to the environment to increase host and network visibility. Threat
intelligence is one of the key products of the IP team during this phase.

Información del documento

Subido en
25 de junio de 2026
Número de páginas
19
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$13.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
TopGradeInsider
4.1
(9)
Vendido
123
Seguidores
2
Artículos
46210
Última venta
1 día hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes