SANS 401 GSEC CORRECT MAIN TIPS QUESTIONS
AND ANSWERS SET A+
✔✔IT Risk Management - ✔✔Identify threats and vulnerabilities to analyze risk
✔✔Single Loss Expectancy (SLE) - ✔✔Loss from a single event.
Asset Value * Exposure Factor= SLE
✔✔Annualized Loss Expectancy (ALE) - ✔✔Annual expected loss based on threat.
SLE * Annualized Rate Occurrence = ALE
✔✔Cost Benefit Analysis - ✔✔Comparison of the cost of implementing
countermeasures with the value of reduced risk
✔✔Workgroups - ✔✔No domain controllers, a standalone computer with local accounts
and local accounts database
✔✔Security ID Number (SID) - ✔✔Each user, computer, and group has a unique SID
✔✔Security Access Token (SAT) - ✔✔Contains SID number of user account and all
groups and privileges. Attached to every process you start where Windows uses the
SAT to check privileges/permissions
✔✔Active Directory - ✔✔A shared registry for all users and computers on the network
✔✔NTLM - ✔✔Predecessor of Kerberos, but still supported
✔✔Group Policy Objects (GPO) - ✔✔Password Policy, Lockout Policy, NTFS
Permissions, Privileges, Event Logs, Registry, Etc.
✔✔Service Pack - ✔✔Large collection of patches
, ✔✔Hotfix - ✔✔A single patch to update an application or OS binary file
✔✔Windows Server Update Service (WSUS) - ✔✔You local automatic updates server.
Can control what patches are deployed
✔✔Binary Image - ✔✔Exact copy backup of a drive with all utilities and configurations
✔✔System Restore - ✔✔Time machine for the Registry and file changes
✔✔PC Reset - ✔✔Complete reinstiall of windows with optional sector scrubbing of disk
✔✔PC Refresh - ✔✔Keep user data, some preferences, and deletes all non-store
applications
✔✔Users have - ✔✔Privileges
✔✔Objects have - ✔✔Permissions
✔✔Windows System Files - ✔✔CDFS, FAT, FAT32, exFAT, ReFS, NTFS
✔✔Hierarchy of Privileges - ✔✔Explicit Deny
Explicit Permit
Implicit Deny
✔✔AGULP - ✔✔How privileges and permissions should be applied
▼Accounts
▼Global Groups
▼Universal Groups
Local Groups
▲Permissions & Rights
✔✔Does the registry have remote access? - ✔✔Yes
✔✔Mandatory Integrity Control - ✔✔A partial implementation of the Biba mandatory
access control model for preserving data integrity
✔✔Best to Worst for Enforcing Security Policy - ✔✔Kerberos
NTLM v2
LAN Manager Authentication Level
NTLM v1
✔✔Network Binding - ✔✔Is an internal communications pathway between networking
components. Each interface has its own separate set of bindings, including VPN and
Wi-Fi
AND ANSWERS SET A+
✔✔IT Risk Management - ✔✔Identify threats and vulnerabilities to analyze risk
✔✔Single Loss Expectancy (SLE) - ✔✔Loss from a single event.
Asset Value * Exposure Factor= SLE
✔✔Annualized Loss Expectancy (ALE) - ✔✔Annual expected loss based on threat.
SLE * Annualized Rate Occurrence = ALE
✔✔Cost Benefit Analysis - ✔✔Comparison of the cost of implementing
countermeasures with the value of reduced risk
✔✔Workgroups - ✔✔No domain controllers, a standalone computer with local accounts
and local accounts database
✔✔Security ID Number (SID) - ✔✔Each user, computer, and group has a unique SID
✔✔Security Access Token (SAT) - ✔✔Contains SID number of user account and all
groups and privileges. Attached to every process you start where Windows uses the
SAT to check privileges/permissions
✔✔Active Directory - ✔✔A shared registry for all users and computers on the network
✔✔NTLM - ✔✔Predecessor of Kerberos, but still supported
✔✔Group Policy Objects (GPO) - ✔✔Password Policy, Lockout Policy, NTFS
Permissions, Privileges, Event Logs, Registry, Etc.
✔✔Service Pack - ✔✔Large collection of patches
, ✔✔Hotfix - ✔✔A single patch to update an application or OS binary file
✔✔Windows Server Update Service (WSUS) - ✔✔You local automatic updates server.
Can control what patches are deployed
✔✔Binary Image - ✔✔Exact copy backup of a drive with all utilities and configurations
✔✔System Restore - ✔✔Time machine for the Registry and file changes
✔✔PC Reset - ✔✔Complete reinstiall of windows with optional sector scrubbing of disk
✔✔PC Refresh - ✔✔Keep user data, some preferences, and deletes all non-store
applications
✔✔Users have - ✔✔Privileges
✔✔Objects have - ✔✔Permissions
✔✔Windows System Files - ✔✔CDFS, FAT, FAT32, exFAT, ReFS, NTFS
✔✔Hierarchy of Privileges - ✔✔Explicit Deny
Explicit Permit
Implicit Deny
✔✔AGULP - ✔✔How privileges and permissions should be applied
▼Accounts
▼Global Groups
▼Universal Groups
Local Groups
▲Permissions & Rights
✔✔Does the registry have remote access? - ✔✔Yes
✔✔Mandatory Integrity Control - ✔✔A partial implementation of the Biba mandatory
access control model for preserving data integrity
✔✔Best to Worst for Enforcing Security Policy - ✔✔Kerberos
NTLM v2
LAN Manager Authentication Level
NTLM v1
✔✔Network Binding - ✔✔Is an internal communications pathway between networking
components. Each interface has its own separate set of bindings, including VPN and
Wi-Fi