100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

SANS FOR578 Book 2 UPDATED Exam Questions and CORRECT Answers

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
17-01-2025
Written in
2024/2025

SANS FOR578 Book 2 UPDATED Exam Questions and CORRECT Answers Kill chain (CTI) - CORRECT ANSWER - - established in 2011 - determanistic process - seven stages to defend Kill chain 7 sreps - CORRECT ANSWER - 1. Reconnaissance and precursors

Show more Read less
Institution
SANS
Course
SANS









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
SANS
Course
SANS

Document information

Uploaded on
January 17, 2025
Number of pages
7
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

SANS FOR578 Book 2 UPDATED Exam
Questions and CORRECT Answers
Kill chain (CTI) - CORRECT ANSWER - - established in 2011
- determanistic process
- seven stages to defend


Kill chain 7 sreps - CORRECT ANSWER - 1. Reconnaissance and precursors
2. Weaponization
3. Delivery
4. Exploitation
5. Installation
6. C2
7. Action on objectives


Stage 1 - recon / precursors - CORRECT ANSWER - - tasking - receipt or generation of
objectives
- acquisition of various tool
- acquisition of infrastructure
- identification of targets
- organizational research


Stage 2 - weaponization - CORRECT ANSWER - - configuring {backdrops, droppers}
- packaging {container, exploit, first stage binary, decoy}


Stage 3 - delivrey - CORRECT ANSWER - - mechanism = payload gets to target
- common vectors {protocol =SMTP,HTTP} or {media = USB, CD, DVD}

, Stage 4 - exploitation - CORRECT ANSWER - - disposition of the exploit {human or
technical}
- affected application
- exploitation method
- characteristics of exploit shellcode


Stage 5 - installation - CORRECT ANSWER - - associated with persistence
- properties of installation {filenames,directories, reg keys, reg values, communication}
- droppers


Stage 6 - C2 command and control - CORRECT ANSWER - - establishing communication
- properties of C2 {Trojan family, MD5, carrier protocol, embedded protocol, infrastructure,
operating mode characteristics}


Stage 7 - action on objectives - CORRECT ANSWER - - commands executed
- additional tools transferred to VI machine
- files extracted
- files modified


Diamond Model - CORRECT ANSWER - - made of 4 parts
- {adversary, capability, infrastructure,victim}
- has 7 AXIOMS


AXIOM 1 - Diamond model - CORRECT ANSWER - In every intrusion event an
adversary takes a step towards an intended goal by using capability over infrastructure against a
victim to produce a result


AXIOM 2 - diamond model - CORRECT ANSWER - There exist a set of adversaries
which seek to compromise computer systems or networks to further their intent and satisfy their
needs

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
MGRADES Stanford University
View profile
Follow You need to be logged in order to follow users or courses
Sold
1074
Member since
1 year
Number of followers
102
Documents
68976
Last sold
1 day ago
MGRADES (Stanford Top Brains)

Welcome to MGRADES Exams, practices and Study materials Just think of me as the plug you will refer to your friends Me and my team will always make sure you get the best value from the exams markets. I offer the best study and exam materials for a wide range of courses and units. Make your study sessions more efficient and effective. Dive in and discover all you need to excel in your academic journey!

3.8

170 reviews

5
73
4
30
3
45
2
8
1
14

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions