SANS MGT514 TEST BANK QUESTIONS AND
ANSWERS GRADED A+ 2026
◉ SMS - Phase 3 (1:120) Answer: Manage relationships is critical to
the success of every project in every organization, so developing a
relationship plan can help you manage your relationships
◉ How to develop an understanding of threats (1:129) Answer:
Understand threat actors - think like your adversaries and
understand their motivations, business assets - identify critical
business assets, Analyzing threats - Understanding adversary TTP's
will help build defense
◉ VERIS (1:132) Answer: Vocabulary for Event Recording and
Incident Sharing - defines a schema and set of metrics to describe
security incidents in a structured and repeatable manner.
◉ VERIS Community Database(1:132) Answer: Free repository of
publicly reported security incidents
◉ Verizon DBIR (1:132) Answer: Verizon Data Breach Investigations
Report - standard way to analyze incidents; mapped and recoded
incidents from other frameworks
,◉ VERIS Threat Actors (1:133) Answer: External - threats from
sources outside the organization; Internal - threats from within
organization; Partner - third party business relationships
◉ NotPetya (1:156) Answer: Variant of Petya ransomware;
encrypted Master Boot Record (MBR); not intended to collect
ransom; most expensive cyber attack in history causing $10 billion
in damages
◉ NotPetya - Attack Tools (1:161) Answer: EternalBlue - takes
advantage of unpatched windows Server Message Block (SMB) that
allows remote code execution; MimiKatz - automates collection of
secrets on Windows including passwords, certificates, LanMAN
hashes; NTLM hashes, Kerberos tickets.
◉ NotPetya - Impact on Maersk (1:164) Answer: 20% reduction in
global shipping equaling $300 million loss; Central booking down;
Software at shipping terminals; IT infrastructure - 45K PC's, 4k
servers, 150 domain controllers had to be rebuilt.
◉ Organizaged Crime (1:169-179) Answer: Target suffered largest
retail attack in US history. After conducting recon, intruders attacked
a trusted vendor using a
◉ Fazio mechanical services (1:173) Answer: Identified as a Target
vendor and exploited via phishing email to an Fazio employee
,◉ Citadel malware (1:173) Answer: password stealing bot program
that is a derivative of Zeus. Attackers were able to harvest
credentials Fazio used to access Targets billing system
◉ Target Attack - Internal Access (1:174) Answer: Attackers were
able to access billing system and due to lack of network
segmentation, they were able to infiltrate POS system and install
BlackPOS on sale terminals.
◉ Target Attack -BlackPOS(1:174) Answer: memory scraping
malware specifically developed that records all credit and debit
cards swiped through the system.
◉ Target Attack - Missed alerts (1:174) Answer: Target employees
ignored security alerts that were meant to inform the Security
Operation Center.
◉ Tangible Assets (1:182) Answer: items such as buildings, data
centers, hospitals, transportation infrastructure, water treatment
facilities, or even residential centers.
◉ Intangible assets (1:183) Answer: Could include customer data -
PII, credit cards, contact info; Employee data - PII, HR data and
internal email communications; Intellectual Property - any "creation
, of the mind" such as music, literature, source code, and courseware,
also including patents, trademarks, copyrights, & trade secrets;
Business proprietary information - business processes, contracts,
mergers & acquisitions & even general business know how.
◉ Most Critical Assets (1:184) Answer: "crown jewels" - data
systems and even processes that are critical to an organization's
competitive and strategic advantage; Change based on industry,
business model or strategy, time horizon.
◉ Tips for identifying crown jewels (1:187) Answer: Start with
business problem, not IT problem, take an enterprise wide review,
engage stakeholders from different business units, product
development, and risk along with security & IT
◉ Health care assets (1:190) Answer: Protected Health Information
(PHI) - offeres financial, credit, and medical fraud opportunities,
Personally Identifiable Information (PII) - contains wealth of
customer/patient information, Payment Card Information (PCI) -
many rely on credit/debit cards sales for prescriptions, co-pays,
cafeteria sales, and gift shop sales; Research data - may have unique
research data that attackers may want to exploit, Key Systems -
attackers may steal data or cause business disruption due to
disagreement
ANSWERS GRADED A+ 2026
◉ SMS - Phase 3 (1:120) Answer: Manage relationships is critical to
the success of every project in every organization, so developing a
relationship plan can help you manage your relationships
◉ How to develop an understanding of threats (1:129) Answer:
Understand threat actors - think like your adversaries and
understand their motivations, business assets - identify critical
business assets, Analyzing threats - Understanding adversary TTP's
will help build defense
◉ VERIS (1:132) Answer: Vocabulary for Event Recording and
Incident Sharing - defines a schema and set of metrics to describe
security incidents in a structured and repeatable manner.
◉ VERIS Community Database(1:132) Answer: Free repository of
publicly reported security incidents
◉ Verizon DBIR (1:132) Answer: Verizon Data Breach Investigations
Report - standard way to analyze incidents; mapped and recoded
incidents from other frameworks
,◉ VERIS Threat Actors (1:133) Answer: External - threats from
sources outside the organization; Internal - threats from within
organization; Partner - third party business relationships
◉ NotPetya (1:156) Answer: Variant of Petya ransomware;
encrypted Master Boot Record (MBR); not intended to collect
ransom; most expensive cyber attack in history causing $10 billion
in damages
◉ NotPetya - Attack Tools (1:161) Answer: EternalBlue - takes
advantage of unpatched windows Server Message Block (SMB) that
allows remote code execution; MimiKatz - automates collection of
secrets on Windows including passwords, certificates, LanMAN
hashes; NTLM hashes, Kerberos tickets.
◉ NotPetya - Impact on Maersk (1:164) Answer: 20% reduction in
global shipping equaling $300 million loss; Central booking down;
Software at shipping terminals; IT infrastructure - 45K PC's, 4k
servers, 150 domain controllers had to be rebuilt.
◉ Organizaged Crime (1:169-179) Answer: Target suffered largest
retail attack in US history. After conducting recon, intruders attacked
a trusted vendor using a
◉ Fazio mechanical services (1:173) Answer: Identified as a Target
vendor and exploited via phishing email to an Fazio employee
,◉ Citadel malware (1:173) Answer: password stealing bot program
that is a derivative of Zeus. Attackers were able to harvest
credentials Fazio used to access Targets billing system
◉ Target Attack - Internal Access (1:174) Answer: Attackers were
able to access billing system and due to lack of network
segmentation, they were able to infiltrate POS system and install
BlackPOS on sale terminals.
◉ Target Attack -BlackPOS(1:174) Answer: memory scraping
malware specifically developed that records all credit and debit
cards swiped through the system.
◉ Target Attack - Missed alerts (1:174) Answer: Target employees
ignored security alerts that were meant to inform the Security
Operation Center.
◉ Tangible Assets (1:182) Answer: items such as buildings, data
centers, hospitals, transportation infrastructure, water treatment
facilities, or even residential centers.
◉ Intangible assets (1:183) Answer: Could include customer data -
PII, credit cards, contact info; Employee data - PII, HR data and
internal email communications; Intellectual Property - any "creation
, of the mind" such as music, literature, source code, and courseware,
also including patents, trademarks, copyrights, & trade secrets;
Business proprietary information - business processes, contracts,
mergers & acquisitions & even general business know how.
◉ Most Critical Assets (1:184) Answer: "crown jewels" - data
systems and even processes that are critical to an organization's
competitive and strategic advantage; Change based on industry,
business model or strategy, time horizon.
◉ Tips for identifying crown jewels (1:187) Answer: Start with
business problem, not IT problem, take an enterprise wide review,
engage stakeholders from different business units, product
development, and risk along with security & IT
◉ Health care assets (1:190) Answer: Protected Health Information
(PHI) - offeres financial, credit, and medical fraud opportunities,
Personally Identifiable Information (PII) - contains wealth of
customer/patient information, Payment Card Information (PCI) -
many rely on credit/debit cards sales for prescriptions, co-pays,
cafeteria sales, and gift shop sales; Research data - may have unique
research data that attackers may want to exploit, Key Systems -
attackers may steal data or cause business disruption due to
disagreement