Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

SANS FOUNDATION SEC275 FINAL PAPER 2026 FULL QUESTIONS AND CORRECT ANSWERS GRADED A+

Document preview thumbnail
Preview 3 out of 24 pages

SANS FOUNDATION SEC275 FINAL PAPER 2026 FULL QUESTIONS AND CORRECT ANSWERS GRADED A+

Content preview

SANS FOUNDATION SEC275 FINAL PAPER 2026
FULL QUESTIONS AND CORRECT ANSWERS
GRADED A+


◉ netstat. Answer: Command used on Linux and Windows (-a -b -o) for
listening to ports to see if an attacker is attempting to connect. Used to
find IoCs


◉ PID. Answer: Process ID


◉ Runlevels. Answer: In UNIX and Linux systems, runlevels indicate
the type of state the
system is in, from 0 (halted), 1 (single user safe mode), 2-5 (multi-user
normal modes) 6 (rebooting). Lower runlevels indicate
maintenance conditions with fewer services running, higher runlevels
are normal
operating conditions.


◉ systemd. Answer: A relatively new software framework used on
Linux systems that provides a system initialization process and system
management functions.

,◉ Startup Folder. Answer: Contains a list of programs that open
automatically when you boot a computer. Simplest way of getting
malware on a user's Windows computer


◉ Rootkits. Answer: software tools used by an attacker to hide actions
or presence of other types of malicious software. Also designed to allow
the attacker back in the system at a later date


◉ Yara. Answer: signature detection tool - the gold standard for
detecting IoCs. It scans a system and compares results with the rules in a
database. It will flag a match as a possible IOC


◉ ARP cache. Answer: A table used to maintain a correlation
between each MAC address and its
corresponding IP address. Meaning any computers that the compromised
computer communicates with will have ARP cache entries.


◉ Mimikatz. Answer: A penetration testing tool used to access RAM to
extract password hashes or plaintext passwords. Often these are valid for
other systems on the network. Can also use hashcat


◉ Man-in-the-middle (MITM) attack. Answer: An attack that relies on
intercepted transmissions. It can take one of several forms, but in all
cases a person redirects or captures secure data traffic while in transit.

, Goal is to intercept password hashes to be able to log into important
systems and file servers. Crack hashes using hashcat


◉ ARP spoofing. Answer: More commonly known as ARP poisoning,
this involves the MAC (Media Access Control) address of the data being
faked by an attacker via the ARP protocol


◉ PsExec. Answer: Designed for network admins to be able to run
PowerShell commands remotely on multiple systems at once


◉ 3 ways to detect exfiltration over HTTPS. Answer: 1. Consider where
the HTTPS traffic is going
2. Set up a network device to use as a proxy and all clients connect
through the proxy
3. Set up a proxy and enable SSL interception on it (configured to trust a
custom SSL certificate)


◉ SMTP Exfiltration. Answer: sending an email through the SMTP
server that the company runs that is hidden within the regular traffic


◉ IRC (Internet Relay Chat). Answer: older chat protocol (plaintext and
no encryption) used a lot in the tech community. Sees a lot of malware
as a command and control channel. Major weakness is that it's an
unusual vector and not often seen in corporate networks.

Document information

Uploaded on
February 22, 2026
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
CA$18.65

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
10
Followers
0
Items
2696
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions