SANS FOR508 CERTIFICATION EVALUATION
EXAMS 2026 SOLVED QUESTIONS 100%
CORRECT
◉ What is the first step of incident response? Answer: - proper
identification of ALL systems compromised
- may be systems compromised with inactive malware
◉ Preparation. Answer: - establish incident response capability
- ensure systems, networks, applications are sufficiently secure
◉ Identification. Answer: - the first step toward proper remediation
◉ Containment & Intel Development. Answer: - identify pivot point
- learn lateral movements of adversary
- identify malware
- use knowledge to engineer countermeasures
**Results in Threat Intelligence**
◉ Remediation. Answer: - actions required over a short period to
mitigate current incident
,◉ What are the six steps (in order) to ensure comprehensive
remediation? Answer: (1) Block malicious IP addresses
(2) Blackhole malicious domain names
(3) Rebuild compromised systems
(4) Coordinate with cloud and service providers
(5) Enterprise password change
(6) Verify all remediation activities
◉ Recovery. Answer: - move back to day-to-day business
- implement long-term solutions
- prevent and detect future incidents
◉ Follow Up. Answer: - verify incident is mitigated (additional
monitoring)
- ensure adversary is removed (network/host sweeps)
- implement additional countermeasures (audit the network)
◉ What are the six steps of Incident Response? Answer: - Preparation
- Identification
- Containment and Intel Development
- Remediation
- Recovery
, - Follow Up
◉ What is one of the key products of the Incident Response team during
an incident? Answer: Threat intelligence
◉ Containment Options. Answer: - enable decoy data sets
- bit mangling
- adversary network segmentation
- full-scale host/network monitoring
- kill switch
◉ Intelligence-driven Incident Response. Answer: - process used to
identify actively new compromised systems
◉ Initial Compromise. Answer: - not usually persistent
◉ Establish foothold/maintain presence. Answer: - maintained presence
despite reboot
◉ Lateral Movement. Answer: - movement within the system
- may use PSEXEC, Scheduled Tasks, or WMI commands
◉ Data Collection. Answer: - generally leaves loud footprint on systems
EXAMS 2026 SOLVED QUESTIONS 100%
CORRECT
◉ What is the first step of incident response? Answer: - proper
identification of ALL systems compromised
- may be systems compromised with inactive malware
◉ Preparation. Answer: - establish incident response capability
- ensure systems, networks, applications are sufficiently secure
◉ Identification. Answer: - the first step toward proper remediation
◉ Containment & Intel Development. Answer: - identify pivot point
- learn lateral movements of adversary
- identify malware
- use knowledge to engineer countermeasures
**Results in Threat Intelligence**
◉ Remediation. Answer: - actions required over a short period to
mitigate current incident
,◉ What are the six steps (in order) to ensure comprehensive
remediation? Answer: (1) Block malicious IP addresses
(2) Blackhole malicious domain names
(3) Rebuild compromised systems
(4) Coordinate with cloud and service providers
(5) Enterprise password change
(6) Verify all remediation activities
◉ Recovery. Answer: - move back to day-to-day business
- implement long-term solutions
- prevent and detect future incidents
◉ Follow Up. Answer: - verify incident is mitigated (additional
monitoring)
- ensure adversary is removed (network/host sweeps)
- implement additional countermeasures (audit the network)
◉ What are the six steps of Incident Response? Answer: - Preparation
- Identification
- Containment and Intel Development
- Remediation
- Recovery
, - Follow Up
◉ What is one of the key products of the Incident Response team during
an incident? Answer: Threat intelligence
◉ Containment Options. Answer: - enable decoy data sets
- bit mangling
- adversary network segmentation
- full-scale host/network monitoring
- kill switch
◉ Intelligence-driven Incident Response. Answer: - process used to
identify actively new compromised systems
◉ Initial Compromise. Answer: - not usually persistent
◉ Establish foothold/maintain presence. Answer: - maintained presence
despite reboot
◉ Lateral Movement. Answer: - movement within the system
- may use PSEXEC, Scheduled Tasks, or WMI commands
◉ Data Collection. Answer: - generally leaves loud footprint on systems