SANS MGT514 FINAL EXAM ACTUAL QUESTIONS AND
ANSWERS SURE A+
✔✔IKC - Weaponization (1:200) - ✔✔created payload that can be delivered to the
target
✔✔IKC - Delivery (1:200) - ✔✔attackers deliver payload to the target typically via email
or web. May also be delivered via USB
✔✔IKC - Exploitation (1:200) - ✔✔after payload delivery, attachment is executed to
exploit a vulnerability on target system
✔✔IKC - Installation (1:200) - ✔✔after gaining access via exploited vulnerability,
attackers can now install malware on system to maintain persistence
✔✔IKC - Command & Control (1:201) - ✔✔backdoor allows for command and control
abilities that enable remote manipulation by the attackers
✔✔IKC - Actions on Objectives (1:201) - ✔✔now with access, attackers can accomplish
their ultimate goals; which may include data exfil, service disruption, or even lateral
movement within the network.
✔✔Threat Analysis based on IOC's - ✔✔Creates intel feedback loop; forces attackers to
adjust TTP's; Results in an increased resilience
✔✔CTI - Cyber Threat Intel (1:206) - ✔✔collection, classification, and exploitation of
knowledge about adversaries that helps defenders reduce their likelihood of success
with each subsequent intrusion attempt.
✔✔CTI - Strategic (1:206) - ✔✔Senior leadership seeks to understand the larger threat
landscape to identify risks to make investment and strategic decisions
✔✔CTI - Operational (1:206) - ✔✔Operational staff look for trends and an adversary's
operation or campaign
✔✔CTI - Tactical (1:206) - ✔✔shows foundational consumption and sharing of IOC's
and attacker TTP's
✔✔STIX (1:206) - ✔✔defines the cyber threat information; language that enables you to
specify and communicate standardized cyber threat information. Sponsored by DHS as
an open community effort
✔✔TAXII (1:207) - ✔✔standardizes the automated exchange of cyber threat
information; Hub & Spoke - one organization serves as the central hub of information
,while others can consume or provide info; Source/Subscriber - One organization
provides info to subscribers; Peer-2-Peer - two or more organizations share information
directly.
✔✔STIX - Threat Actor(1:208) - ✔✔Individuals, groups, or organizations believed to be
operating with malicious intent
✔✔STIX - Campaign (1:208) - ✔✔Grouping of adversarial behaviors that describes a
set of malicious activities or attacks that occur over a period of time against a specific
set of targets
✔✔STIX - Intrusion Set (1:208) - ✔✔grouped set of adversarial behaviors and
resources with common properties believed to be orchestrated by a single threat actor
✔✔STIX - Attack Pattern (1:208) - ✔✔type of TTP's that describe ways threat actors
attempt to compromise targets
✔✔STIX - Malware (1:208) - ✔✔type of TTP, AKA malicious code or software used to
compromise the CIA triangle of a victims data or system
✔✔STIX - Tool (1:208) - ✔✔Legitimate software that can be used by threat actors to
perform attacks
✔✔STIX - Vulnerability (1:208) - ✔✔A mistake in software that can be directly used by a
hacker to gain access to a system or network
✔✔STIX - Indicator (1:208) - ✔✔Contains a pattern that can be used to detect
suspicious or malicious cyber activity
✔✔STIX - identity (1:208) - ✔✔Individuals, Organizations, or groups, as well as classes
of individuals, organziations, or groups
✔✔STIX - Observed Data (1:208) - ✔✔conveys info observed on a system or network
(i.e. - IP address_
✔✔STIX - Course of action (1:208) - ✔✔Action taken to either prevent or respond to an
attack.
✔✔External Threat Intel Sources (1:209) - ✔✔Open: SANS, OSINT, Mitre, CERTs;
Private: FS-ISAC, NH-ISAC, REN-ISAC; Commerical: AlienVault, Anomali, Crowdstrike,
Dell Secureworks, FireEye/Mandiant, McAfee, OpenDNS/Cisco, Palo Alto, Recorded
Future, iDefense/Accenture
, ✔✔Internal threat intel sources (1:210) - ✔✔many internal logs that can be analyzed for
intel; Database, directory, DLP, DNS, Email, Firewall, HR info, IDS/IPS, Malware,
Physical Access, VPN, Web/WAF
✔✔Cyber threat intel key elements (1:211) - ✔✔what should you look for from a threat
intel source: Can be consumed & parsed automatically, use of standard framework,
IOCs that can be shared, capability to normalize indicators
✔✔COA - Course of Action Matrix (1:220) - ✔✔Various techniques that can be used
against attackers during various phases of the kill chain
✔✔COA - Detect (1:220) - ✔✔Web & Audit logs, along with NIDS/HIDS systems,
provide a wealth of information about potential attacker activity.
✔✔COA - Deny (1:220) - ✔✔Firewalls, ACLs, NIPS, proxy filtering, and antivirus can
provide a means to block attacks. Patching vulnerabilities and running in a "chroot" jail
which prevents software from access files outside it's own root directory
✔✔COA - Disrupt (1:220) - ✔✔Attacks can be disrupted using a number of techniques
such as in-line Antivirus & NIPS. To disrupt the exploitation phase, software can also be
built with Data Execution Prevention - which is a feature that marks certain area of
memory as "nonexecutable"
✔✔COA - Degrage (1:220) - ✔✔Queuing requests or decreasing the quality of service
by using tarpits or purposely delay connections
✔✔COA - Deceive (1:221) - ✔✔Attackers can be deceived by DNS redirects or
honeypots that appear to be part of the real system, but are isolated systems
specifically monitored to analyze attacks.
✔✔Define Current state (2:4) - ✔✔Understanding what the company is trying to achieve
- know the vision and mission; Understand how you operate - knowing the
organizational values & culture; Understand where you are strong & weak - complete
SWOT analysis.
✔✔Vision Statement (2:7) - ✔✔What's the organization want to be in the longer term -
it's goals and aspirations. the "Why" they company exists and it's noble , seemingly
unreachable goal
✔✔Mission Statement (2:7) - ✔✔What the organization does today - it's current
purpose, what it does and for whom
✔✔Vision Statement - Purpose (2:8) - ✔✔What the company hopes to be when it
"grows up"
ANSWERS SURE A+
✔✔IKC - Weaponization (1:200) - ✔✔created payload that can be delivered to the
target
✔✔IKC - Delivery (1:200) - ✔✔attackers deliver payload to the target typically via email
or web. May also be delivered via USB
✔✔IKC - Exploitation (1:200) - ✔✔after payload delivery, attachment is executed to
exploit a vulnerability on target system
✔✔IKC - Installation (1:200) - ✔✔after gaining access via exploited vulnerability,
attackers can now install malware on system to maintain persistence
✔✔IKC - Command & Control (1:201) - ✔✔backdoor allows for command and control
abilities that enable remote manipulation by the attackers
✔✔IKC - Actions on Objectives (1:201) - ✔✔now with access, attackers can accomplish
their ultimate goals; which may include data exfil, service disruption, or even lateral
movement within the network.
✔✔Threat Analysis based on IOC's - ✔✔Creates intel feedback loop; forces attackers to
adjust TTP's; Results in an increased resilience
✔✔CTI - Cyber Threat Intel (1:206) - ✔✔collection, classification, and exploitation of
knowledge about adversaries that helps defenders reduce their likelihood of success
with each subsequent intrusion attempt.
✔✔CTI - Strategic (1:206) - ✔✔Senior leadership seeks to understand the larger threat
landscape to identify risks to make investment and strategic decisions
✔✔CTI - Operational (1:206) - ✔✔Operational staff look for trends and an adversary's
operation or campaign
✔✔CTI - Tactical (1:206) - ✔✔shows foundational consumption and sharing of IOC's
and attacker TTP's
✔✔STIX (1:206) - ✔✔defines the cyber threat information; language that enables you to
specify and communicate standardized cyber threat information. Sponsored by DHS as
an open community effort
✔✔TAXII (1:207) - ✔✔standardizes the automated exchange of cyber threat
information; Hub & Spoke - one organization serves as the central hub of information
,while others can consume or provide info; Source/Subscriber - One organization
provides info to subscribers; Peer-2-Peer - two or more organizations share information
directly.
✔✔STIX - Threat Actor(1:208) - ✔✔Individuals, groups, or organizations believed to be
operating with malicious intent
✔✔STIX - Campaign (1:208) - ✔✔Grouping of adversarial behaviors that describes a
set of malicious activities or attacks that occur over a period of time against a specific
set of targets
✔✔STIX - Intrusion Set (1:208) - ✔✔grouped set of adversarial behaviors and
resources with common properties believed to be orchestrated by a single threat actor
✔✔STIX - Attack Pattern (1:208) - ✔✔type of TTP's that describe ways threat actors
attempt to compromise targets
✔✔STIX - Malware (1:208) - ✔✔type of TTP, AKA malicious code or software used to
compromise the CIA triangle of a victims data or system
✔✔STIX - Tool (1:208) - ✔✔Legitimate software that can be used by threat actors to
perform attacks
✔✔STIX - Vulnerability (1:208) - ✔✔A mistake in software that can be directly used by a
hacker to gain access to a system or network
✔✔STIX - Indicator (1:208) - ✔✔Contains a pattern that can be used to detect
suspicious or malicious cyber activity
✔✔STIX - identity (1:208) - ✔✔Individuals, Organizations, or groups, as well as classes
of individuals, organziations, or groups
✔✔STIX - Observed Data (1:208) - ✔✔conveys info observed on a system or network
(i.e. - IP address_
✔✔STIX - Course of action (1:208) - ✔✔Action taken to either prevent or respond to an
attack.
✔✔External Threat Intel Sources (1:209) - ✔✔Open: SANS, OSINT, Mitre, CERTs;
Private: FS-ISAC, NH-ISAC, REN-ISAC; Commerical: AlienVault, Anomali, Crowdstrike,
Dell Secureworks, FireEye/Mandiant, McAfee, OpenDNS/Cisco, Palo Alto, Recorded
Future, iDefense/Accenture
, ✔✔Internal threat intel sources (1:210) - ✔✔many internal logs that can be analyzed for
intel; Database, directory, DLP, DNS, Email, Firewall, HR info, IDS/IPS, Malware,
Physical Access, VPN, Web/WAF
✔✔Cyber threat intel key elements (1:211) - ✔✔what should you look for from a threat
intel source: Can be consumed & parsed automatically, use of standard framework,
IOCs that can be shared, capability to normalize indicators
✔✔COA - Course of Action Matrix (1:220) - ✔✔Various techniques that can be used
against attackers during various phases of the kill chain
✔✔COA - Detect (1:220) - ✔✔Web & Audit logs, along with NIDS/HIDS systems,
provide a wealth of information about potential attacker activity.
✔✔COA - Deny (1:220) - ✔✔Firewalls, ACLs, NIPS, proxy filtering, and antivirus can
provide a means to block attacks. Patching vulnerabilities and running in a "chroot" jail
which prevents software from access files outside it's own root directory
✔✔COA - Disrupt (1:220) - ✔✔Attacks can be disrupted using a number of techniques
such as in-line Antivirus & NIPS. To disrupt the exploitation phase, software can also be
built with Data Execution Prevention - which is a feature that marks certain area of
memory as "nonexecutable"
✔✔COA - Degrage (1:220) - ✔✔Queuing requests or decreasing the quality of service
by using tarpits or purposely delay connections
✔✔COA - Deceive (1:221) - ✔✔Attackers can be deceived by DNS redirects or
honeypots that appear to be part of the real system, but are isolated systems
specifically monitored to analyze attacks.
✔✔Define Current state (2:4) - ✔✔Understanding what the company is trying to achieve
- know the vision and mission; Understand how you operate - knowing the
organizational values & culture; Understand where you are strong & weak - complete
SWOT analysis.
✔✔Vision Statement (2:7) - ✔✔What's the organization want to be in the longer term -
it's goals and aspirations. the "Why" they company exists and it's noble , seemingly
unreachable goal
✔✔Mission Statement (2:7) - ✔✔What the organization does today - it's current
purpose, what it does and for whom
✔✔Vision Statement - Purpose (2:8) - ✔✔What the company hopes to be when it
"grows up"