SANS MGT514 UPDATED EXAM SCRIPT QUESTIONS
AND ANSWERS SURE A+
✔✔PEST - S - Social (1:65,78) - ✔✔Looks at cultural aspects of the market and how
they affect the demand for a company's products and/or services; customer needs and
determine what incents them to make purchases
✔✔PEST - T - Technological (1:65,81) - ✔✔How technology can either positively or
negatively impact a business and the products and/or services they provide. i.e.
technology advancements, life cycle of technologies, technology innovation
✔✔SMS - stakeholder management strategy(1:91) - ✔✔Technology deployment could
impact not only security, but also the enterprise. All stakeholders and impact need to be
identified and managed
✔✔SMS - Stakeholder(1:95) - ✔✔People or groups with a vested interest in the success
of your strategy and who will affect of be affected by your team's work.
✔✔SMS - Phase 1(1:98,99) - ✔✔Identifying stakeholders - hold a meeting with your
team of managers and staff to brainstorm who key stakeholders might be
✔✔SIPOC - Stakeholder ID Tool - ✔✔SIPOC (Suppliers, Inputs, Processes, Outputs, &
Customers)
✔✔SIPOC - Suppliers (1:102,112) - ✔✔Those people/groups who provide inputs
✔✔SIPOC - Inputs (1:102,111) - ✔✔key requirements needed for the process to work.
Should represent information/materials the suppliers provide to you.
✔✔SIPOC - Processes (1:102,106) - ✔✔defined series of activities;
✔✔SIPOC - Outputs (1:102,108) - ✔✔tangible results of the process steps.
✔✔SIPOC - Customers (1:102,110) - ✔✔recipients/users of the outputs produced at
every step in the process.
✔✔SMS - Phase 2 (1:114) - ✔✔Understanding Stakeholder motivation
✔✔SMS - Phase 2 - Step 1 (1:114) - ✔✔Understand stakeholders - meeting with them
will help you better understand what motivates them, what they want/need from you,
what interests they have in your work.
✔✔SMS - Phase 2 - Step 2 (1:114) - ✔✔Mapping Power and Interest - three levels of
power veto, vote, voice; Three levels of interest - High, medium, low
,✔✔SMS - Phase 2 - Step 3 (1:114) - ✔✔Prioritize Stakeholders - High power/interested
people, high power/less interested people, Low power/interested people, Low
power/less interested people
✔✔SMS - Phase 3 (1:120) - ✔✔Manage relationships is critical to the success of every
project in every organization, so developing a relationship plan can help you manage
your relationships
✔✔How to develop an understanding of threats (1:129) - ✔✔Understand threat actors -
think like your adversaries and understand their motivations, business assets - identify
critical business assets, Analyzing threats - Understanding adversary TTP's will help
build defense
✔✔VERIS (1:132) - ✔✔Vocabulary for Event Recording and Incident Sharing - defines
a schema and set of metrics to describe security incidents in a structured and
repeatable manner.
✔✔VERIS Community Database(1:132) - ✔✔Free repository of publicly reported
security incidents
✔✔Verizon DBIR (1:132) - ✔✔Verizon Data Breach Investigations Report - standard
way to analyze incidents; mapped and recoded incidents from other frameworks
✔✔VERIS Threat Actors (1:133) - ✔✔External - threats from sources outside the
organization; Internal - threats from within organization; Partner - third party business
relationships
✔✔NotPetya (1:156) - ✔✔Variant of Petya ransomware; encrypted Master Boot Record
(MBR); not intended to collect ransom; most expensive cyber attack in history causing
$10 billion in damages
✔✔NotPetya - Attack Tools (1:161) - ✔✔EternalBlue - takes advantage of unpatched
windows Server Message Block (SMB) that allows remote code execution; MimiKatz -
automates collection of secrets on Windows including passwords, certificates, LanMAN
hashes; NTLM hashes, Kerberos tickets.
✔✔NotPetya - Impact on Maersk (1:164) - ✔✔20% reduction in global shipping equaling
$300 million loss; Central booking down; Software at shipping terminals; IT
infrastructure - 45K PC's, 4k servers, 150 domain controllers had to be rebuilt.
✔✔Organizaged Crime (1:169-179) - ✔✔Target suffered largest retail attack in US
history. After conducting recon, intruders attacked a trusted vendor using a
, ✔✔Fazio mechanical services (1:173) - ✔✔Identified as a Target vendor and exploited
via phishing email to an Fazio employee
✔✔Citadel malware (1:173) - ✔✔password stealing bot program that is a derivative of
Zeus. Attackers were able to harvest credentials Fazio used to access Targets billing
system
✔✔Target Attack - Internal Access (1:174) - ✔✔Attackers were able to access billing
system and due to lack of network segmentation, they were able to infiltrate POS
system and install BlackPOS on sale terminals.
✔✔Target Attack -BlackPOS(1:174) - ✔✔memory scraping malware specifically
developed that records all credit and debit cards swiped through the system.
✔✔Target Attack - Missed alerts (1:174) - ✔✔Target employees ignored security alerts
that were meant to inform the Security Operation Center.
✔✔Tangible Assets (1:182) - ✔✔items such as buildings, data centers, hospitals,
transportation infrastructure, water treatment facilities, or even residential centers.
✔✔Intangible assets (1:183) - ✔✔Could include customer data - PII, credit cards,
contact info; Employee data - PII, HR data and internal email communications;
Intellectual Property - any "creation of the mind" such as music, literature, source code,
and courseware, also including patents, trademarks, copyrights, & trade secrets;
Business proprietary information - business processes, contracts, mergers &
acquisitions & even general business know how.
✔✔Most Critical Assets (1:184) - ✔✔"crown jewels" - data systems and even processes
that are critical to an organization's competitive and strategic advantage; Change based
on industry, business model or strategy, time horizon.
✔✔Tips for identifying crown jewels (1:187) - ✔✔Start with business problem, not IT
problem, take an enterprise wide review, engage stakeholders from different business
units, product development, and risk along with security & IT
✔✔Health care assets (1:190) - ✔✔Protected Health Information (PHI) - offeres
financial, credit, and medical fraud opportunities, Personally Identifiable Information (PII)
- contains wealth of customer/patient information, Payment Card Information (PCI) -
many rely on credit/debit cards sales for prescriptions, co-pays, cafeteria sales, and gift
shop sales; Research data - may have unique research data that attackers may want to
exploit, Key Systems - attackers may steal data or cause business disruption due to
disagreement
✔✔Risk Analysis (1:197) - ✔✔Combination of the impact and likelihood of an event; or
to analyze the vulnerability and threat components.
AND ANSWERS SURE A+
✔✔PEST - S - Social (1:65,78) - ✔✔Looks at cultural aspects of the market and how
they affect the demand for a company's products and/or services; customer needs and
determine what incents them to make purchases
✔✔PEST - T - Technological (1:65,81) - ✔✔How technology can either positively or
negatively impact a business and the products and/or services they provide. i.e.
technology advancements, life cycle of technologies, technology innovation
✔✔SMS - stakeholder management strategy(1:91) - ✔✔Technology deployment could
impact not only security, but also the enterprise. All stakeholders and impact need to be
identified and managed
✔✔SMS - Stakeholder(1:95) - ✔✔People or groups with a vested interest in the success
of your strategy and who will affect of be affected by your team's work.
✔✔SMS - Phase 1(1:98,99) - ✔✔Identifying stakeholders - hold a meeting with your
team of managers and staff to brainstorm who key stakeholders might be
✔✔SIPOC - Stakeholder ID Tool - ✔✔SIPOC (Suppliers, Inputs, Processes, Outputs, &
Customers)
✔✔SIPOC - Suppliers (1:102,112) - ✔✔Those people/groups who provide inputs
✔✔SIPOC - Inputs (1:102,111) - ✔✔key requirements needed for the process to work.
Should represent information/materials the suppliers provide to you.
✔✔SIPOC - Processes (1:102,106) - ✔✔defined series of activities;
✔✔SIPOC - Outputs (1:102,108) - ✔✔tangible results of the process steps.
✔✔SIPOC - Customers (1:102,110) - ✔✔recipients/users of the outputs produced at
every step in the process.
✔✔SMS - Phase 2 (1:114) - ✔✔Understanding Stakeholder motivation
✔✔SMS - Phase 2 - Step 1 (1:114) - ✔✔Understand stakeholders - meeting with them
will help you better understand what motivates them, what they want/need from you,
what interests they have in your work.
✔✔SMS - Phase 2 - Step 2 (1:114) - ✔✔Mapping Power and Interest - three levels of
power veto, vote, voice; Three levels of interest - High, medium, low
,✔✔SMS - Phase 2 - Step 3 (1:114) - ✔✔Prioritize Stakeholders - High power/interested
people, high power/less interested people, Low power/interested people, Low
power/less interested people
✔✔SMS - Phase 3 (1:120) - ✔✔Manage relationships is critical to the success of every
project in every organization, so developing a relationship plan can help you manage
your relationships
✔✔How to develop an understanding of threats (1:129) - ✔✔Understand threat actors -
think like your adversaries and understand their motivations, business assets - identify
critical business assets, Analyzing threats - Understanding adversary TTP's will help
build defense
✔✔VERIS (1:132) - ✔✔Vocabulary for Event Recording and Incident Sharing - defines
a schema and set of metrics to describe security incidents in a structured and
repeatable manner.
✔✔VERIS Community Database(1:132) - ✔✔Free repository of publicly reported
security incidents
✔✔Verizon DBIR (1:132) - ✔✔Verizon Data Breach Investigations Report - standard
way to analyze incidents; mapped and recoded incidents from other frameworks
✔✔VERIS Threat Actors (1:133) - ✔✔External - threats from sources outside the
organization; Internal - threats from within organization; Partner - third party business
relationships
✔✔NotPetya (1:156) - ✔✔Variant of Petya ransomware; encrypted Master Boot Record
(MBR); not intended to collect ransom; most expensive cyber attack in history causing
$10 billion in damages
✔✔NotPetya - Attack Tools (1:161) - ✔✔EternalBlue - takes advantage of unpatched
windows Server Message Block (SMB) that allows remote code execution; MimiKatz -
automates collection of secrets on Windows including passwords, certificates, LanMAN
hashes; NTLM hashes, Kerberos tickets.
✔✔NotPetya - Impact on Maersk (1:164) - ✔✔20% reduction in global shipping equaling
$300 million loss; Central booking down; Software at shipping terminals; IT
infrastructure - 45K PC's, 4k servers, 150 domain controllers had to be rebuilt.
✔✔Organizaged Crime (1:169-179) - ✔✔Target suffered largest retail attack in US
history. After conducting recon, intruders attacked a trusted vendor using a
, ✔✔Fazio mechanical services (1:173) - ✔✔Identified as a Target vendor and exploited
via phishing email to an Fazio employee
✔✔Citadel malware (1:173) - ✔✔password stealing bot program that is a derivative of
Zeus. Attackers were able to harvest credentials Fazio used to access Targets billing
system
✔✔Target Attack - Internal Access (1:174) - ✔✔Attackers were able to access billing
system and due to lack of network segmentation, they were able to infiltrate POS
system and install BlackPOS on sale terminals.
✔✔Target Attack -BlackPOS(1:174) - ✔✔memory scraping malware specifically
developed that records all credit and debit cards swiped through the system.
✔✔Target Attack - Missed alerts (1:174) - ✔✔Target employees ignored security alerts
that were meant to inform the Security Operation Center.
✔✔Tangible Assets (1:182) - ✔✔items such as buildings, data centers, hospitals,
transportation infrastructure, water treatment facilities, or even residential centers.
✔✔Intangible assets (1:183) - ✔✔Could include customer data - PII, credit cards,
contact info; Employee data - PII, HR data and internal email communications;
Intellectual Property - any "creation of the mind" such as music, literature, source code,
and courseware, also including patents, trademarks, copyrights, & trade secrets;
Business proprietary information - business processes, contracts, mergers &
acquisitions & even general business know how.
✔✔Most Critical Assets (1:184) - ✔✔"crown jewels" - data systems and even processes
that are critical to an organization's competitive and strategic advantage; Change based
on industry, business model or strategy, time horizon.
✔✔Tips for identifying crown jewels (1:187) - ✔✔Start with business problem, not IT
problem, take an enterprise wide review, engage stakeholders from different business
units, product development, and risk along with security & IT
✔✔Health care assets (1:190) - ✔✔Protected Health Information (PHI) - offeres
financial, credit, and medical fraud opportunities, Personally Identifiable Information (PII)
- contains wealth of customer/patient information, Payment Card Information (PCI) -
many rely on credit/debit cards sales for prescriptions, co-pays, cafeteria sales, and gift
shop sales; Research data - may have unique research data that attackers may want to
exploit, Key Systems - attackers may steal data or cause business disruption due to
disagreement
✔✔Risk Analysis (1:197) - ✔✔Combination of the impact and likelihood of an event; or
to analyze the vulnerability and threat components.