SANS 515 EXAM LATEST
Purpose of ICS Incident Response - ANSWERS-1. Maintain safe and
reliable operations
2. Acquire meaningful forensic data
3. Perform timely analysis
4. Contain and eradicate threats
Order of Volatility - ANSWERS-1. When performing acquisition
through the collection of digital images and network traffic, the order of
volatility should be followed
2. The order of volatility is a way to describe what evidence is most
likely to be destroyed first
3. The general Order of Volatility is:
1. Cache and Register content
2. Network information
3. Memory
4. System processes
5. Temporary filesystem
6. data on hard disk
7. remotely logged data
8. data on archival media
END OF
PAGE
1
, SANS 515 EXAM LATEST
Local Versus Remote Acquisition - ANSWERS-1. It should be
performed whenever possible. Local Acquisition is faster and often
easier
2. Certain conditions must be met to justify it. Remote acquisition is
slower and has an element of risk
Chain of Command - ANSWERS-1. Evidence and Incident Handlers:
Acquire evidence, scope infection, timely analysis
2. Lead Responder: Response for all handers. Guides personnel, triage,
timeline, maintains sitional awareness
3. Incident Response Director: Interfaces with management/PoCs. Pre-
incident focus point
Defensible Cyber Position During Incident Response - ANSWERS-1.
Disconnect Internet access
2. Disable currently unused features
3. Limit or disable remote connections
4. Additional security protocols for staff
END OF
PAGE
2
, SANS 515 EXAM LATEST
PDF Aspects to Focus On - ANSWERS-Focus on specific pdf file
formats because they have been observed in various malicious instances
AnalyzePDF - ANSWERS-Python script that uses PDFID, Pdinfo, Yara
rules to analyze PDFs
VPNs - ANSWERS-1. Heavily used in most ICS environments for
business -> control network communication and for vendor -> ICS
access across the WAN
2. Observed to be abused
3. Viewable Logs
Cloud and Virtual Resources - ANSWERS-1. Use vendors to check
cloud resources for compromises and acquire digintal evidence
2. on-site cloud resources or VMs use system memory that can be
collected and analyzed.
3. .vmem in vmware: paging file
4. vmdk in vmware is virtual disk
5. copying files over can be as good as loading systems and attempting
to run forensic acquisition software
END OF
PAGE
3
Purpose of ICS Incident Response - ANSWERS-1. Maintain safe and
reliable operations
2. Acquire meaningful forensic data
3. Perform timely analysis
4. Contain and eradicate threats
Order of Volatility - ANSWERS-1. When performing acquisition
through the collection of digital images and network traffic, the order of
volatility should be followed
2. The order of volatility is a way to describe what evidence is most
likely to be destroyed first
3. The general Order of Volatility is:
1. Cache and Register content
2. Network information
3. Memory
4. System processes
5. Temporary filesystem
6. data on hard disk
7. remotely logged data
8. data on archival media
END OF
PAGE
1
, SANS 515 EXAM LATEST
Local Versus Remote Acquisition - ANSWERS-1. It should be
performed whenever possible. Local Acquisition is faster and often
easier
2. Certain conditions must be met to justify it. Remote acquisition is
slower and has an element of risk
Chain of Command - ANSWERS-1. Evidence and Incident Handlers:
Acquire evidence, scope infection, timely analysis
2. Lead Responder: Response for all handers. Guides personnel, triage,
timeline, maintains sitional awareness
3. Incident Response Director: Interfaces with management/PoCs. Pre-
incident focus point
Defensible Cyber Position During Incident Response - ANSWERS-1.
Disconnect Internet access
2. Disable currently unused features
3. Limit or disable remote connections
4. Additional security protocols for staff
END OF
PAGE
2
, SANS 515 EXAM LATEST
PDF Aspects to Focus On - ANSWERS-Focus on specific pdf file
formats because they have been observed in various malicious instances
AnalyzePDF - ANSWERS-Python script that uses PDFID, Pdinfo, Yara
rules to analyze PDFs
VPNs - ANSWERS-1. Heavily used in most ICS environments for
business -> control network communication and for vendor -> ICS
access across the WAN
2. Observed to be abused
3. Viewable Logs
Cloud and Virtual Resources - ANSWERS-1. Use vendors to check
cloud resources for compromises and acquire digintal evidence
2. on-site cloud resources or VMs use system memory that can be
collected and analyzed.
3. .vmem in vmware: paging file
4. vmdk in vmware is virtual disk
5. copying files over can be as good as loading systems and attempting
to run forensic acquisition software
END OF
PAGE
3