SANS 515 UPDATED EXAMINATION TEST 2026
TESTED QUESTIONS WITH FULL SOLUTION
GRADED A+
◉ What is an inherent security benefit of having system services
listening only on unique local address (ULA) IPv6 addresses instead
of global unicast addresses (GUA)?
A) ULA addresses are used to fully anonymize the source, thus
improving privacy.
B) ULA addresses are not publicly routed, creating a layer of
isolation from the Internet.
C) ULA addresses do not offer an inherent security improvement
over GUA addresses.
D) ULA addresses are used to fully anonymize the destination, this
improving privacy. Answer: B) ULA addresses are not publicly
routed, creating a layer of isolation from the Internet.
◉ Which of the following NIST special publications brings guidelines
for the secure development of IPv6?
A) NIST SP 800-119
B) NIST SP 800-53
,C) NIST SP 800-86
D) NIST SP 800-68 Answer: A) NIST SP 800-119
◉ In which scenario must IPv6 hosts use duplicate address
detection (DAD) to determine whether an address is already in use
on the network?
A) When systems use DHCPv6 to obtain an address and stateless
address autoconfiguration is enabled.
B) When systems use stateless address autoconfiguration to
generate an IP address and privacy extensions are enabled.
C) When systems use DHCPv6 to obtain an address and privacy
extensions are disabled.
D) When systems use stateless address autoconfiguration to
generate addresses and privacy extensions are disabled. Answer: B)
When systems use stateless address autoconfiguration to generate
an IP address and privacy extensions are enabled.
◉ Which of the following solutions would work for ensuring
accurate NTP synchronized time across devices on an air-gapped
network with no connectivity to untrusted networks such as the
Internet?
A) NTP time synchronization cannot be enabled for an air-gapped
network.
,B) Purchase and deploy stratum one time server locally.
C) Leverage the free authenticated NTP services that NIST makes
available.
D) Deploy an Internet-based time server and volunteer to serve in
the ntp.org pool. Answer: B) Purchase and deploy stratum one time
server locally.
◉ The NTP "monlist" command can be abused to facilitate which
type of attack?
A) An NTP time skew attack.
B) An NTP amplification attack.
C) An NTP session hijacking attack.
D) An NTP time zone attack. Answer: B) An NTP amplification
attack.
◉ What does the NTP *monlist* command do? Answer: The NTP
monlist command requests the NTP server to respond with a list of
up to 600 NTP client systems that have recently queried the server.
◉ Which statement is true regarding the Linux Iptables firewall?
A) A system with no configured output chain will allow all outbound
traffic.
, B) Iptables supports INPUT, OUTPUT, and FORWARD tables.
C) Iptables supports FILTER, MANGLE, and NAT chains.
D) A system with no configured output chain will block all outbound
traffic. Answer: A) A system with no configured output chain will
allow all outbound traffic.
◉ What is the name of the DNS TXT record that helps validate email
to verify whether it is sent from an authorized source based on
authorized IP addresses?
A) DomainKeys Identified Mail
B) Mailer Exchange
C) Sender Policy Framework
D) Host Info Answer: C) Sender Policy Framework
◉ Which of the following network device configuration auditing
tools is free, currently maintained, and available for use by any
organization?
A) Nipper Studio
B) CISecurity's CIS-CAT Pro
C) CISecurity's Router Audit Tool
D) Nipper-ng Answer: D) Nipper-ng
TESTED QUESTIONS WITH FULL SOLUTION
GRADED A+
◉ What is an inherent security benefit of having system services
listening only on unique local address (ULA) IPv6 addresses instead
of global unicast addresses (GUA)?
A) ULA addresses are used to fully anonymize the source, thus
improving privacy.
B) ULA addresses are not publicly routed, creating a layer of
isolation from the Internet.
C) ULA addresses do not offer an inherent security improvement
over GUA addresses.
D) ULA addresses are used to fully anonymize the destination, this
improving privacy. Answer: B) ULA addresses are not publicly
routed, creating a layer of isolation from the Internet.
◉ Which of the following NIST special publications brings guidelines
for the secure development of IPv6?
A) NIST SP 800-119
B) NIST SP 800-53
,C) NIST SP 800-86
D) NIST SP 800-68 Answer: A) NIST SP 800-119
◉ In which scenario must IPv6 hosts use duplicate address
detection (DAD) to determine whether an address is already in use
on the network?
A) When systems use DHCPv6 to obtain an address and stateless
address autoconfiguration is enabled.
B) When systems use stateless address autoconfiguration to
generate an IP address and privacy extensions are enabled.
C) When systems use DHCPv6 to obtain an address and privacy
extensions are disabled.
D) When systems use stateless address autoconfiguration to
generate addresses and privacy extensions are disabled. Answer: B)
When systems use stateless address autoconfiguration to generate
an IP address and privacy extensions are enabled.
◉ Which of the following solutions would work for ensuring
accurate NTP synchronized time across devices on an air-gapped
network with no connectivity to untrusted networks such as the
Internet?
A) NTP time synchronization cannot be enabled for an air-gapped
network.
,B) Purchase and deploy stratum one time server locally.
C) Leverage the free authenticated NTP services that NIST makes
available.
D) Deploy an Internet-based time server and volunteer to serve in
the ntp.org pool. Answer: B) Purchase and deploy stratum one time
server locally.
◉ The NTP "monlist" command can be abused to facilitate which
type of attack?
A) An NTP time skew attack.
B) An NTP amplification attack.
C) An NTP session hijacking attack.
D) An NTP time zone attack. Answer: B) An NTP amplification
attack.
◉ What does the NTP *monlist* command do? Answer: The NTP
monlist command requests the NTP server to respond with a list of
up to 600 NTP client systems that have recently queried the server.
◉ Which statement is true regarding the Linux Iptables firewall?
A) A system with no configured output chain will allow all outbound
traffic.
, B) Iptables supports INPUT, OUTPUT, and FORWARD tables.
C) Iptables supports FILTER, MANGLE, and NAT chains.
D) A system with no configured output chain will block all outbound
traffic. Answer: A) A system with no configured output chain will
allow all outbound traffic.
◉ What is the name of the DNS TXT record that helps validate email
to verify whether it is sent from an authorized source based on
authorized IP addresses?
A) DomainKeys Identified Mail
B) Mailer Exchange
C) Sender Policy Framework
D) Host Info Answer: C) Sender Policy Framework
◉ Which of the following network device configuration auditing
tools is free, currently maintained, and available for use by any
organization?
A) Nipper Studio
B) CISecurity's CIS-CAT Pro
C) CISecurity's Router Audit Tool
D) Nipper-ng Answer: D) Nipper-ng