SANS FOR508 COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
● RegRipper. Answer: - automated HIVE parser - can parse the following HIVES: SAM,
SECURITY, SYSTEM, SOFTWARE, NTUSER.DAT - also used to parse restore point registry
files
● What is the first step of incident response?. Answer: - proper identification of ALL
systems compromised - may be systems compromised with inactive malware
● Preparation. Answer: - establish incident response capability - ensure systems, networks,
applications are sufficiently secure
● Identification. Answer: - the first step toward proper remediation
● Containment & Intel Development. Answer: - identify pivot point - learn lateral
movements of adversary - identify malware - use knowledge to engineer countermeasures
*Results in Threat Intelligence*
● Remediation. Answer: - actions required over a short period to mitigate current incident
● What are the six steps (in order) to ensure comprehensive remediation?. Answer: (1)
Block malicious IP addresses (2) Blackhole malicious domain names (3) Rebuild
compromised systems (4) Coordinate with cloud and service providers (5) Enterprise
password change (6) Verify all remediation activities
● Recovery. Answer: - move back to day-to-day business - implement long-term solutions -
prevent and detect future incidents
● Follow Up. Answer: - verify incident is mitigated (additional monitoring) - ensure adversary
is removed (network/host sweeps) - implement additional countermeasures (audit the
network)
● What are the six steps of Incident Response?. Answer: - Preparation - Identification -
Containment and Intel Development - Remediation - Recovery - Follow Up
● What is one of the key products of the Incident Response team during an incident?.
Answer: Threat intelligence
, ● Containment Options. Answer: - enable decoy data sets - bit mangling - adversary
network segmentation - full-scale host/network monitoring - kill switch
● Intelligence-driven Incident Response. Answer: - process used to identify actively new
compromised systems
● Initial Compromise. Answer: - not usually persistent
● Establish foothold/maintain presence. Answer: - maintained presence despite reboot
● Lateral Movement. Answer: - movement within the system - may use PSEXEC, Scheduled
Tasks, or WMI commands
● Data Collection. Answer: - generally leaves loud footprint on systems
● Data exfil. Answer: - may be detected by automated SIEM - easiest to detect
● Deep-dive Forensics. Answer: - memory analysis (all processes) - Timeline analysis (all
activity) - File system analysis (all)
● Enterprise Scanning. Answer: - memory analysis (specific processes) - Timeline analysis
(specific activity) - File system analysis (specific)
● 3 Steps of Remediation Event (Plan). Answer: - Posture - Execute - Implement controls
● 4 Remediation Event Goals. Answer: - deny access - restrict reaction - remove presence -
degrade survivability
● Actions to increase monitoring:. Answer: - full content packet captures on compromised
segments - full netflow data from all egress pts - retain and maintain DHCP, VPN, firewall, and
Web logs
● Critical Remediation Event Steps (8). Answer: - Disconnect environment from Internet -
Implement strict segmentation - Block IPs and domain names for C2 channels - Remove
infected systems - Remove all ID'd systems (those not active) - Restrict access to known
comp. accounts - Restrict access to domain admin accounts - Validate proper steps taken
● Risk. Answer: Comprised of vulnerability, impact, and threat
● Vulnerability. Answer: mutable and ephemeral
● Impact. Answer: immutable and changes are slow or non-existent
QUESTIONS AND SOLUTIONS GRADED A+
● RegRipper. Answer: - automated HIVE parser - can parse the following HIVES: SAM,
SECURITY, SYSTEM, SOFTWARE, NTUSER.DAT - also used to parse restore point registry
files
● What is the first step of incident response?. Answer: - proper identification of ALL
systems compromised - may be systems compromised with inactive malware
● Preparation. Answer: - establish incident response capability - ensure systems, networks,
applications are sufficiently secure
● Identification. Answer: - the first step toward proper remediation
● Containment & Intel Development. Answer: - identify pivot point - learn lateral
movements of adversary - identify malware - use knowledge to engineer countermeasures
*Results in Threat Intelligence*
● Remediation. Answer: - actions required over a short period to mitigate current incident
● What are the six steps (in order) to ensure comprehensive remediation?. Answer: (1)
Block malicious IP addresses (2) Blackhole malicious domain names (3) Rebuild
compromised systems (4) Coordinate with cloud and service providers (5) Enterprise
password change (6) Verify all remediation activities
● Recovery. Answer: - move back to day-to-day business - implement long-term solutions -
prevent and detect future incidents
● Follow Up. Answer: - verify incident is mitigated (additional monitoring) - ensure adversary
is removed (network/host sweeps) - implement additional countermeasures (audit the
network)
● What are the six steps of Incident Response?. Answer: - Preparation - Identification -
Containment and Intel Development - Remediation - Recovery - Follow Up
● What is one of the key products of the Incident Response team during an incident?.
Answer: Threat intelligence
, ● Containment Options. Answer: - enable decoy data sets - bit mangling - adversary
network segmentation - full-scale host/network monitoring - kill switch
● Intelligence-driven Incident Response. Answer: - process used to identify actively new
compromised systems
● Initial Compromise. Answer: - not usually persistent
● Establish foothold/maintain presence. Answer: - maintained presence despite reboot
● Lateral Movement. Answer: - movement within the system - may use PSEXEC, Scheduled
Tasks, or WMI commands
● Data Collection. Answer: - generally leaves loud footprint on systems
● Data exfil. Answer: - may be detected by automated SIEM - easiest to detect
● Deep-dive Forensics. Answer: - memory analysis (all processes) - Timeline analysis (all
activity) - File system analysis (all)
● Enterprise Scanning. Answer: - memory analysis (specific processes) - Timeline analysis
(specific activity) - File system analysis (specific)
● 3 Steps of Remediation Event (Plan). Answer: - Posture - Execute - Implement controls
● 4 Remediation Event Goals. Answer: - deny access - restrict reaction - remove presence -
degrade survivability
● Actions to increase monitoring:. Answer: - full content packet captures on compromised
segments - full netflow data from all egress pts - retain and maintain DHCP, VPN, firewall, and
Web logs
● Critical Remediation Event Steps (8). Answer: - Disconnect environment from Internet -
Implement strict segmentation - Block IPs and domain names for C2 channels - Remove
infected systems - Remove all ID'd systems (those not active) - Restrict access to known
comp. accounts - Restrict access to domain admin accounts - Validate proper steps taken
● Risk. Answer: Comprised of vulnerability, impact, and threat
● Vulnerability. Answer: mutable and ephemeral
● Impact. Answer: immutable and changes are slow or non-existent