SANS SEC401 Module Quizzes Updated
Exam Questions And 100% Verified
Answers Latest 2026 Update | Graded
A+ | 100% Success
What is the goal of an output-driven log filtering method?
a) Log and keep everything.
b) Log only what you know you need.
c) Drop duplicate log entries.
d) Drop unnecessary low-volume logs. - Correct Answer -b) Log only what you
know you need.
- book 3, page 169
What is a type of malware that is historically self-replicating and carries one or
more exploits or payloads?
a) Trojan
b) Virus
c) Backdoor
d) Worm - Correct Answer -d) Worm
,- book 3, page 112
Which of the following is the practice of looking at a problem or situation from the
perspective of an adversary when the customer is the blue team?
a) Penetration test
b) Red team
c) Vulnerability assessment
d) Purple team - Correct Answer -b) Red Team
- book 3, page 37
What are the three components used in temporal score metrics?
a) Exploitability, report confidence, remediation level
b) Exploitability, impact metrics, remediation level
c) Base modifiers, report confidence, impact metrics
d) Base modifiers, remediation level, impact metrics - Correct Answer -a)
Exploitability, report confidence, remediation level
- book 3, page 26
,Which phase of a vulnerability assessment validates documentation and network
diagrams?
a) Remediation
b) Validation
c) Discovery
d) Scanning - Correct Answer -c) Discovery
- book 3, page 16
Which malware's goal is the destruction of data?
a) Backdoor
b) Worms
c) Virus
d) Ransomware - Correct Answer -c) Virus
- book 3, page 113
Of the following groupings, which is used as base modifiers in the environmental
score metrics for CVSS Version 3 calculations?
a) Privileges required, user interaction, scope
b) User interaction, attack vector, availability requirement
, c) User interaction, scope, confidentiality requirement
d) Privileges required, scope, confidentiality requirement - Correct Answer -a)
Privileges required, user interaction, scope
- book 3, page 25
Once a list of vulnerabilities has been generated by a scanner, what is the next
step in a vulnerability assessment?
a) Report vulnerabilities
b) Remediate vulnerabilities
c) Validate vulnerabilities
d) Sort vulnerabilities according to their CVE score - Correct Answer -c) Validate
vulnerabilities
- book 3, page 18
During which phase of the incident response process is a system be isolated from
the rest of the network?
a) Recovery
b) Identification
c) Containment
d) Eradication - Correct Answer -c) Containment
Exam Questions And 100% Verified
Answers Latest 2026 Update | Graded
A+ | 100% Success
What is the goal of an output-driven log filtering method?
a) Log and keep everything.
b) Log only what you know you need.
c) Drop duplicate log entries.
d) Drop unnecessary low-volume logs. - Correct Answer -b) Log only what you
know you need.
- book 3, page 169
What is a type of malware that is historically self-replicating and carries one or
more exploits or payloads?
a) Trojan
b) Virus
c) Backdoor
d) Worm - Correct Answer -d) Worm
,- book 3, page 112
Which of the following is the practice of looking at a problem or situation from the
perspective of an adversary when the customer is the blue team?
a) Penetration test
b) Red team
c) Vulnerability assessment
d) Purple team - Correct Answer -b) Red Team
- book 3, page 37
What are the three components used in temporal score metrics?
a) Exploitability, report confidence, remediation level
b) Exploitability, impact metrics, remediation level
c) Base modifiers, report confidence, impact metrics
d) Base modifiers, remediation level, impact metrics - Correct Answer -a)
Exploitability, report confidence, remediation level
- book 3, page 26
,Which phase of a vulnerability assessment validates documentation and network
diagrams?
a) Remediation
b) Validation
c) Discovery
d) Scanning - Correct Answer -c) Discovery
- book 3, page 16
Which malware's goal is the destruction of data?
a) Backdoor
b) Worms
c) Virus
d) Ransomware - Correct Answer -c) Virus
- book 3, page 113
Of the following groupings, which is used as base modifiers in the environmental
score metrics for CVSS Version 3 calculations?
a) Privileges required, user interaction, scope
b) User interaction, attack vector, availability requirement
, c) User interaction, scope, confidentiality requirement
d) Privileges required, scope, confidentiality requirement - Correct Answer -a)
Privileges required, user interaction, scope
- book 3, page 25
Once a list of vulnerabilities has been generated by a scanner, what is the next
step in a vulnerability assessment?
a) Report vulnerabilities
b) Remediate vulnerabilities
c) Validate vulnerabilities
d) Sort vulnerabilities according to their CVE score - Correct Answer -c) Validate
vulnerabilities
- book 3, page 18
During which phase of the incident response process is a system be isolated from
the rest of the network?
a) Recovery
b) Identification
c) Containment
d) Eradication - Correct Answer -c) Containment