SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS
WITH ANSWERS GRADED A+
● Dwell Time. Answer: Time an attacker has remained undetected in the network.
● Breakout Time. Answer: Time it takes an attacker to begin moving laterally once initiated
foothold in network.
● Incident Response Process (Six Steps). Answer: 1. Preparation. 2.
Identification/Scoping. 3. Containment/Intelligence Development. 4. Eradication/Remediation.
5. Recovery. 6. Lessons Learned/Threat Intel Consumption.
● Preparation - Step 1 of IR Process. Answer: Establishing a response capability &
preventing incidents by ensuring systems, networks, & apps sufficiently secure.
● Identification/Scoping - Step 2 of IR Process. Answer: Triggered by suspicious event.
Event validation should occur, decision made as to severity (not valid events lead to full IR
response. One IR begun, phase used to better understand findings & begin scoping network
for addt'l compromise.
● Containment/Intel Development - Step 3 of IR Process. Answer: Goal to rapidly
understand adversary begin crafting containment strategy. Identify initial exploit, how
attackers maintaining persistence & laterally moving, how C2 being accomplished. Implement
changes to increase host/network visibility. Threat intel key part of phase.
● Eradication/Remediation - Step 4 of IR Process. Answer: Arguably most important
phase. Aim to remove threat, restore ops to normal state. Ex. changes to environment: -Block
malicious IP addresses; blackhole malicious domain names; rebuild compromised systems;
coordinate w/cloud & service providers; Enterprise-wide password changes; implementation
validation
● Recovery - Step 5 of IR Process. Answer: leads enterprise back to day-to-day business.
Goal is to improve overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility; Establish
Comprehensive Patch Mgmt Program; Centralized Logging (SIEM/SIM); Enhance Password
Portal; Establish Security Awareness Training Program; Network Redesign
, ● Follow-Up - Step 6 of IR Process. Answer: Verify incident mitigated, adversary removed,
addt'l countermeasures implemented correctly. Addt'l monitoring, network sweeps looking for
new breaches, auditing network (pen tests) to ensure new security functioning normally
● Eradication w/o Proper Scoping/Containment. Answer: Many orgs begin eradication too
quickly. Stop gap measures (pulling plug, blocking IP addresses, rebuilding systems,
disabling compromised accts) unlikely to lead to full eradication. "whack-a-mole" when move
too fast to eradication.
● Containment/Intel Development - Step 3 of IR Process. Answer: Bulk of response time
often spent here. Need for threat intel collection can't be overstated. IOC development
important at this phase. W/enough intel, possible to predict attacker intent/future actions.
When this point reached, time to consider eradication phase.
● Compromised Host. Answer: Any system the adversary has examined, utilized, or
infected.
● Remediation Is Hard. Answer: Threats good at avoiding detection & ensuring survivability.
Threats react to countermeasures & remediation tactics. Threats will return.
● Intel Development. Answer: Tools, techniques, & procedures observation; Understanding
adversary intent; Malware gathering; IOC development; Campaign identification
● Containment. Answer: Prevent or slow addt'l access during monitoring & collection phase;
Full-scale host/network monitoring; data decoy; bit mangling; traffic shaping; adversary
network segmentation. AVOID PLAYING YOUR HAND.
● Identification/Scoping & Containment/Intel Development Loop. Answer: These 2
critical phases form mini-cycle. Intel developed used for further scoping. New systems
analyzed, providing addt'l info on actions & new IOCs, which then used to find more systems.
● Remediation - Critical Event Steps. Answer: 1. Disconnect environment from network. 2.
Implement strict network segmentation not allowing specific subnets to communicate w/each
other. 3. Block IP addresses & domain names for known C2 channels. 4. Remove all infected
systems that maintained active or previous active malware on host. 5. If needed, remove all
systems id'd as compromised but do not show sings of infection via malware. 6. Restrict
access to known compromised accts. 7. Restrict access to domain admin accts. 8. Validate
everything above done properly.
● Remediation - Real-Time. Answer: Advances in network & endpoint monitoring provide
some organizations ability to mitigate attacks in real-time. It requires complete enterprise
visibility & mature processes.
WITH ANSWERS GRADED A+
● Dwell Time. Answer: Time an attacker has remained undetected in the network.
● Breakout Time. Answer: Time it takes an attacker to begin moving laterally once initiated
foothold in network.
● Incident Response Process (Six Steps). Answer: 1. Preparation. 2.
Identification/Scoping. 3. Containment/Intelligence Development. 4. Eradication/Remediation.
5. Recovery. 6. Lessons Learned/Threat Intel Consumption.
● Preparation - Step 1 of IR Process. Answer: Establishing a response capability &
preventing incidents by ensuring systems, networks, & apps sufficiently secure.
● Identification/Scoping - Step 2 of IR Process. Answer: Triggered by suspicious event.
Event validation should occur, decision made as to severity (not valid events lead to full IR
response. One IR begun, phase used to better understand findings & begin scoping network
for addt'l compromise.
● Containment/Intel Development - Step 3 of IR Process. Answer: Goal to rapidly
understand adversary begin crafting containment strategy. Identify initial exploit, how
attackers maintaining persistence & laterally moving, how C2 being accomplished. Implement
changes to increase host/network visibility. Threat intel key part of phase.
● Eradication/Remediation - Step 4 of IR Process. Answer: Arguably most important
phase. Aim to remove threat, restore ops to normal state. Ex. changes to environment: -Block
malicious IP addresses; blackhole malicious domain names; rebuild compromised systems;
coordinate w/cloud & service providers; Enterprise-wide password changes; implementation
validation
● Recovery - Step 5 of IR Process. Answer: leads enterprise back to day-to-day business.
Goal is to improve overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility; Establish
Comprehensive Patch Mgmt Program; Centralized Logging (SIEM/SIM); Enhance Password
Portal; Establish Security Awareness Training Program; Network Redesign
, ● Follow-Up - Step 6 of IR Process. Answer: Verify incident mitigated, adversary removed,
addt'l countermeasures implemented correctly. Addt'l monitoring, network sweeps looking for
new breaches, auditing network (pen tests) to ensure new security functioning normally
● Eradication w/o Proper Scoping/Containment. Answer: Many orgs begin eradication too
quickly. Stop gap measures (pulling plug, blocking IP addresses, rebuilding systems,
disabling compromised accts) unlikely to lead to full eradication. "whack-a-mole" when move
too fast to eradication.
● Containment/Intel Development - Step 3 of IR Process. Answer: Bulk of response time
often spent here. Need for threat intel collection can't be overstated. IOC development
important at this phase. W/enough intel, possible to predict attacker intent/future actions.
When this point reached, time to consider eradication phase.
● Compromised Host. Answer: Any system the adversary has examined, utilized, or
infected.
● Remediation Is Hard. Answer: Threats good at avoiding detection & ensuring survivability.
Threats react to countermeasures & remediation tactics. Threats will return.
● Intel Development. Answer: Tools, techniques, & procedures observation; Understanding
adversary intent; Malware gathering; IOC development; Campaign identification
● Containment. Answer: Prevent or slow addt'l access during monitoring & collection phase;
Full-scale host/network monitoring; data decoy; bit mangling; traffic shaping; adversary
network segmentation. AVOID PLAYING YOUR HAND.
● Identification/Scoping & Containment/Intel Development Loop. Answer: These 2
critical phases form mini-cycle. Intel developed used for further scoping. New systems
analyzed, providing addt'l info on actions & new IOCs, which then used to find more systems.
● Remediation - Critical Event Steps. Answer: 1. Disconnect environment from network. 2.
Implement strict network segmentation not allowing specific subnets to communicate w/each
other. 3. Block IP addresses & domain names for known C2 channels. 4. Remove all infected
systems that maintained active or previous active malware on host. 5. If needed, remove all
systems id'd as compromised but do not show sings of infection via malware. 6. Restrict
access to known compromised accts. 7. Restrict access to domain admin accts. 8. Validate
everything above done properly.
● Remediation - Real-Time. Answer: Advances in network & endpoint monitoring provide
some organizations ability to mitigate attacks in real-time. It requires complete enterprise
visibility & mature processes.