SANS 515 ACTUAL EXAM PAPER 2026
QUESTIONS WITH ANSWERS GRADED
A+
◍ Dwell Time.
Answer: The time an attacker has remained undetected within a network. An
important metric to track as it directly correlates with the ability of an
attacker to accomplish their objectives.
◍ Ack Piggybacking.
Answer: The Practice of sending an ACK inside another packet going to the
same destination
◍ Address resolution protocol.
Answer: Protocol for mapping an IP address to a physical machine address
that is recognized on the local network. A table, usually called the ARP
cache, is used to maintain a correlation between each MAC and its
corresponding IP address
◍ Breakout Time.
Answer: Time is takes an intruder to begin moving laterally once they have
an initial foothold in the network.
◍ What are the five threat vectors?.
Answer: Outside attack from networkOutsider attack from telephoneInsider
attack from local networkinsider attack from local systemattack from
malicious code
◍ What are some external threat concerns?.
Answer: -Malicious code might execute destructive overwrite to hard
disks-Malicious mas mailing code might expose sensitive information to the
internet- web server compromise might expose organization to ridicule-
, Web server compromise might expose customer private data
◍ Main Threat Actors.
Answer: APT (Nation State Actors)Organized CrimeHacktivists
◍ What are some ways to bypass firewall protections?.
Answer: - Worms and Wireless- modems- tunnel anything through HTTP-
social engineering
◍ What is social engineering?.
Answer: - attempt to manipulate or trick a person into providing information
or access- bypass network security by exploiting humans- vector is often
outside attack by telephone or visitor inside
◍ NIST.
Answer: US National Institute for Standards and Technology
◍ Six-Step Incident Response Process.
Answer: 1: Preparation2: Identification3: Containment and Intelligence
Development4: Eradication and Remediation5: Recovery6: Follow-up
◍ Six-Step - Preparation.
Answer: Incident response methodologies emphasize preparation-not only
establishing a response capability so the organization is ready to respond to
incidents but also preventing incidents by ensuring that systems, networks,
and applications are sufficiently secure.
◍ Six-Step - Identificatoin.
Answer: Identification is triggered by a suspicious event. This could be from
a security appliance, a call to the help-desk, or the result of something
discovered via threat hunting. Event validation should occur and a decision
made as to the severity of the finding (not valid events lead to a full incident
response). Once an incident response has begun, this phase is used to better
understand the findings and begin scoping the network for additional
compromise.
◍ What is Hping?.
, Answer: - a TCP version of ping- sends custom TCP packets to a host and
listens for replies- enables port scanning and spoofing simultaneously
◍ What is a group?.
Answer: A group means multiple iterations won't matter. If you encrypt with
a key, then re-encrypt, it's the same as using one key.
◍ Six Step - Containment and Intelligence development.
Answer: In this phase, the goal is to rapidly understand the adversary and
begin crafting a containment strategy. Responders must identify the initial
vulnerability or exploit, how the attackers are maintaining persistence and
laterally moving in the network, and how command and control is being
accomplished. in conjunction with the previous scoping phase, responders
will work to have a complete picture of the attack and often implement
changes to the environment to increase host and network visibility. Threat
intelligence is one of the key products of the IP team during this phase.
◍ Six Step - Eradication and Remediation.
Answer: Arguably the most important phase of the process, eradication aims
to remove the threat and restore business operations to a normal state.
However, successful eradication cannot occur until the full scop of the
intrusion is understood. A rush to this phase usually results in failure.
Remediation plans are developed, and recommendations are implemented in
a planned and controlled manner. Ex. Include-Block malicious IP
addresses-Blackhole malicious domain names-Rebuild compromised
systems-Coordinate with cloud and service providers-Enterprise-wide
password changes-Implementation validation
◍ Recovery.
Answer: Recovery leads the enterprise back to day-to-day business. The
organization will have learned a lot during the incident investigation and
will invariably have many changes to implement to make the enterprise
more defensible. Recovery plans are typically divided into near-, mid-, and
long-term goals, and near-term changes should start immediately. The foal
during this phase is to improve the overall security of the network and to
, detect and prevent immediate reinfection. Some recovery models
include-Improve Enterprise Authentication Model-Enhanced Network
Visibility -Establish comprehensive Patch Management Program-Enforce
Change Management Program-Centralized Logging (SIM/SIEM)-Enhance
Password Portal-Establish Security Awareness Training Program-Network
Redesign
◍ What is a port scan?.
Answer: - common backdoor to open a port- port scan scans for open ports
on remote host- scans 0 - 65,535 twice. TCP and UDP
◍ Follow-Up.
Answer: Follow-Up is used to verify the incident has been mitigated, the
adversary has been removed, and additional countermeasures have been
implemented correctly. This step combines additional monitoring, network
sweeps looking for new breaches, and auditing the network 9penetration
tests and compliance) to ensure new security mechanisms are in place and
functioning normally.
◍ What is nmap?.
Answer: Network scanner.
◍ What are nmap scanning techniques?.
Answer: - Full open- half open (stealth scan)- UDP- Ping
◍ What is network stumbler?.
Answer: - free windows based wireless scanner for 802.1b- detects access
point settings- supports GSP integration- identifies networks as encrypted or
unencrypted
◍ What is Kismet?.
Answer: - Free linux WLAN analysis tool- completely passive, cannot be
detected- supports advanced GPS integration and mapping features- used for
wardriving, WLAN vulerability assessment
◍ Problem with the Six-Step incident response process.
Answer: Few teams follow the process as prescribed. Pressure leading to
QUESTIONS WITH ANSWERS GRADED
A+
◍ Dwell Time.
Answer: The time an attacker has remained undetected within a network. An
important metric to track as it directly correlates with the ability of an
attacker to accomplish their objectives.
◍ Ack Piggybacking.
Answer: The Practice of sending an ACK inside another packet going to the
same destination
◍ Address resolution protocol.
Answer: Protocol for mapping an IP address to a physical machine address
that is recognized on the local network. A table, usually called the ARP
cache, is used to maintain a correlation between each MAC and its
corresponding IP address
◍ Breakout Time.
Answer: Time is takes an intruder to begin moving laterally once they have
an initial foothold in the network.
◍ What are the five threat vectors?.
Answer: Outside attack from networkOutsider attack from telephoneInsider
attack from local networkinsider attack from local systemattack from
malicious code
◍ What are some external threat concerns?.
Answer: -Malicious code might execute destructive overwrite to hard
disks-Malicious mas mailing code might expose sensitive information to the
internet- web server compromise might expose organization to ridicule-
, Web server compromise might expose customer private data
◍ Main Threat Actors.
Answer: APT (Nation State Actors)Organized CrimeHacktivists
◍ What are some ways to bypass firewall protections?.
Answer: - Worms and Wireless- modems- tunnel anything through HTTP-
social engineering
◍ What is social engineering?.
Answer: - attempt to manipulate or trick a person into providing information
or access- bypass network security by exploiting humans- vector is often
outside attack by telephone or visitor inside
◍ NIST.
Answer: US National Institute for Standards and Technology
◍ Six-Step Incident Response Process.
Answer: 1: Preparation2: Identification3: Containment and Intelligence
Development4: Eradication and Remediation5: Recovery6: Follow-up
◍ Six-Step - Preparation.
Answer: Incident response methodologies emphasize preparation-not only
establishing a response capability so the organization is ready to respond to
incidents but also preventing incidents by ensuring that systems, networks,
and applications are sufficiently secure.
◍ Six-Step - Identificatoin.
Answer: Identification is triggered by a suspicious event. This could be from
a security appliance, a call to the help-desk, or the result of something
discovered via threat hunting. Event validation should occur and a decision
made as to the severity of the finding (not valid events lead to a full incident
response). Once an incident response has begun, this phase is used to better
understand the findings and begin scoping the network for additional
compromise.
◍ What is Hping?.
, Answer: - a TCP version of ping- sends custom TCP packets to a host and
listens for replies- enables port scanning and spoofing simultaneously
◍ What is a group?.
Answer: A group means multiple iterations won't matter. If you encrypt with
a key, then re-encrypt, it's the same as using one key.
◍ Six Step - Containment and Intelligence development.
Answer: In this phase, the goal is to rapidly understand the adversary and
begin crafting a containment strategy. Responders must identify the initial
vulnerability or exploit, how the attackers are maintaining persistence and
laterally moving in the network, and how command and control is being
accomplished. in conjunction with the previous scoping phase, responders
will work to have a complete picture of the attack and often implement
changes to the environment to increase host and network visibility. Threat
intelligence is one of the key products of the IP team during this phase.
◍ Six Step - Eradication and Remediation.
Answer: Arguably the most important phase of the process, eradication aims
to remove the threat and restore business operations to a normal state.
However, successful eradication cannot occur until the full scop of the
intrusion is understood. A rush to this phase usually results in failure.
Remediation plans are developed, and recommendations are implemented in
a planned and controlled manner. Ex. Include-Block malicious IP
addresses-Blackhole malicious domain names-Rebuild compromised
systems-Coordinate with cloud and service providers-Enterprise-wide
password changes-Implementation validation
◍ Recovery.
Answer: Recovery leads the enterprise back to day-to-day business. The
organization will have learned a lot during the incident investigation and
will invariably have many changes to implement to make the enterprise
more defensible. Recovery plans are typically divided into near-, mid-, and
long-term goals, and near-term changes should start immediately. The foal
during this phase is to improve the overall security of the network and to
, detect and prevent immediate reinfection. Some recovery models
include-Improve Enterprise Authentication Model-Enhanced Network
Visibility -Establish comprehensive Patch Management Program-Enforce
Change Management Program-Centralized Logging (SIM/SIEM)-Enhance
Password Portal-Establish Security Awareness Training Program-Network
Redesign
◍ What is a port scan?.
Answer: - common backdoor to open a port- port scan scans for open ports
on remote host- scans 0 - 65,535 twice. TCP and UDP
◍ Follow-Up.
Answer: Follow-Up is used to verify the incident has been mitigated, the
adversary has been removed, and additional countermeasures have been
implemented correctly. This step combines additional monitoring, network
sweeps looking for new breaches, and auditing the network 9penetration
tests and compliance) to ensure new security mechanisms are in place and
functioning normally.
◍ What is nmap?.
Answer: Network scanner.
◍ What are nmap scanning techniques?.
Answer: - Full open- half open (stealth scan)- UDP- Ping
◍ What is network stumbler?.
Answer: - free windows based wireless scanner for 802.1b- detects access
point settings- supports GSP integration- identifies networks as encrypted or
unencrypted
◍ What is Kismet?.
Answer: - Free linux WLAN analysis tool- completely passive, cannot be
detected- supports advanced GPS integration and mapping features- used for
wardriving, WLAN vulerability assessment
◍ Problem with the Six-Step incident response process.
Answer: Few teams follow the process as prescribed. Pressure leading to