Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A

Document preview thumbnail
Preview 2 out of 6 pages

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A

Content preview

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS
WITH ANSWERS GRADED A+


● Dwell Time. Answer: Time an attacker has remained undetected in the network.

● Breakout Time. Answer: Time it takes an attacker to begin moving laterally once initiated
foothold in network.

● Incident Response Process (Six Steps). Answer: 1. Preparation. 2.
Identification/Scoping. 3. Containment/Intelligence Development. 4. Eradication/Remediation.
5. Recovery. 6. Lessons Learned/Threat Intel Consumption.

● Preparation - Step 1 of IR Process. Answer: Establishing a response capability &
preventing incidents by ensuring systems, networks, & apps sufficiently secure.

● Identification/Scoping - Step 2 of IR Process. Answer: Triggered by suspicious event.
Event validation should occur, decision made as to severity (not valid events lead to full IR
response. One IR begun, phase used to better understand findings & begin scoping network
for addt'l compromise.

● Containment/Intel Development - Step 3 of IR Process. Answer: Goal to rapidly
understand adversary begin crafting containment strategy. Identify initial exploit, how
attackers maintaining persistence & laterally moving, how C2 being accomplished. Implement
changes to increase host/network visibility. Threat intel key part of phase.

● Eradication/Remediation - Step 4 of IR Process. Answer: Arguably most important
phase. Aim to remove threat, restore ops to normal state. Ex. changes to environment: -Block
malicious IP addresses; blackhole malicious domain names; rebuild compromised systems;
coordinate w/cloud & service providers; Enterprise-wide password changes; implementation
validation

● Recovery - Step 5 of IR Process. Answer: leads enterprise back to day-to-day business.
Goal is to improve overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility; Establish
Comprehensive Patch Mgmt Program; Centralized Logging (SIEM/SIM); Enhance Password
Portal; Establish Security Awareness Training Program; Network Redesign

, ● Follow-Up - Step 6 of IR Process. Answer: Verify incident mitigated, adversary removed,
addt'l countermeasures implemented correctly. Addt'l monitoring, network sweeps looking for
new breaches, auditing network (pen tests) to ensure new security functioning normally

● Eradication w/o Proper Scoping/Containment. Answer: Many orgs begin eradication too
quickly. Stop gap measures (pulling plug, blocking IP addresses, rebuilding systems,
disabling compromised accts) unlikely to lead to full eradication. "whack-a-mole" when move
too fast to eradication.

● Containment/Intel Development - Step 3 of IR Process. Answer: Bulk of response time
often spent here. Need for threat intel collection can't be overstated. IOC development
important at this phase. W/enough intel, possible to predict attacker intent/future actions.
When this point reached, time to consider eradication phase.

● Compromised Host. Answer: Any system the adversary has examined, utilized, or
infected.

● Remediation Is Hard. Answer: Threats good at avoiding detection & ensuring survivability.
Threats react to countermeasures & remediation tactics. Threats will return.

● Intel Development. Answer: Tools, techniques, & procedures observation; Understanding
adversary intent; Malware gathering; IOC development; Campaign identification

● Containment. Answer: Prevent or slow addt'l access during monitoring & collection phase;
Full-scale host/network monitoring; data decoy; bit mangling; traffic shaping; adversary
network segmentation. AVOID PLAYING YOUR HAND.

● Identification/Scoping & Containment/Intel Development Loop. Answer: These 2
critical phases form mini-cycle. Intel developed used for further scoping. New systems
analyzed, providing addt'l info on actions & new IOCs, which then used to find more systems.

● Remediation - Critical Event Steps. Answer: 1. Disconnect environment from network. 2.
Implement strict network segmentation not allowing specific subnets to communicate w/each
other. 3. Block IP addresses & domain names for known C2 channels. 4. Remove all infected
systems that maintained active or previous active malware on host. 5. If needed, remove all
systems id'd as compromised but do not show sings of infection via malware. 6. Restrict
access to known compromised accts. 7. Restrict access to domain admin accts. 8. Validate
everything above done properly.

● Remediation - Real-Time. Answer: Advances in network & endpoint monitoring provide
some organizations ability to mitigate attacks in real-time. It requires complete enterprise
visibility & mature processes.

Document information

Uploaded on
March 7, 2026
Number of pages
6
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
32
Followers
1
Items
14355
Last sold
4 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions