Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 27 pages
Exam (elaborations)

SANS FOR 508 Exam PRACTICE Questions,MULTICHOICE ANSWERS WITH RATIONALES UPDATED VERSION OF 2026/2027

Document preview thumbnail
Preview 3 out of 27 pages

SANS FOR 508 Exam PRACTICE Questions,MULTICHOICE ANSWERS WITH RATIONALES UPDATED VERSION OF 2026/2027

Content preview

SANS FOR 508 ExAm PRACTICE QuESTIONS,muLTICHOICE
ANSWERS WITH RATIONALES <uPDATED VERSION OF
2026/2027>


1. what does "dwell time" measure in incident response?
a) the time an attacker takes to break into the network
b) the time an attacker remains undetected within a network
c) the time to contain an incident
d) the time to recover from an attack

correct answer: b
rationale: according to the text, dwell time is the time an attacker has remained undetected within a
network, directly correlating with their ability to accomplish objectives.




2. what is "breakout time"?
a) time to detect an intrusion
b) time it takes an intruder to begin moving laterally once they have an initial foothold
c) time to eradicate malware
d) time to notify management

correct answer: b
rationale: the text defines breakout time as the time an intruder takes to begin moving laterally after
gaining an initial foothold.




3. which of the following is listed as a main threat actor?
a) disgruntled employees only
b) apt (nation state actors), organized crime, hacktivists
c) script kiddies only
d) competitors only

correct answer: b
rationale: the text explicitly lists apt (nation state actors), organized crime, and hacktivists as main
threat actors.




4. what does nist stand for?

,a) national institute for security technology
b) national institute for standards and technology
c) north american institute for security testing
d) network incident security team

correct answer: b
rationale: the text states nist = us national institute for standards and technology.




5. how many steps are in the sixstep incident response process?
a) four
b) five
c) six
d) seven

correct answer: c
rationale: the text lists a sixstep incident response process: preparation, identification, containment
and intelligence development, eradication and remediation, recovery, followup.




6. which step emphasizes preventing incidents by ensuring systems are sufficiently secure?
a) identification
b) containment
c) preparation
d) recovery

correct answer: c
rationale: the text states preparation includes not only response capability but also preventing
incidents by securing systems, networks, and applications.




7. what triggers the identification step?
a) a scheduled audit
b) a suspicious event from a security appliance, helpdesk call, or threat hunting
c) an annual budget review
d) a management request

correct answer: b
rationale: according to the text, identification is triggered by a suspicious event, such as from a
security appliance, helpdesk call, or threat hunting.

, 8. during which phase do responders identify the initial vulnerability and how attackers maintain
persistence?
a) preparation
b) identification
c) containment and intelligence development
d) followup

correct answer: c
rationale: the text states that in containment and intelligence development, responders identify the
initial vulnerability, persistence, lateral movement, and c2.




9. what is a key product of the incident response team during the containment and intelligence
development phase?
a) financial audit
b) threat intelligence
c) employee training schedule
d) marketing plan

correct answer: b
rationale: the text says threat intelligence is one of the key products of the ir team during this phase.




10. which phase is described as arguably the most important?
a) preparation
b) identification
c) eradication and remediation
d) followup

correct answer: c
rationale: the text states eradication and remediation is "arguably the most important phase of the
process."




11. what is the risk of rushing to the eradication and remediation phase?
a) faster recovery
b) lower costs
c) failure because full scope of intrusion is not understood
d) improved employee morale

Document information

Uploaded on
June 5, 2026
Number of pages
27
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.42

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
0
Items
237
Last sold
-


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions