SANS 515 CERTIFICATION SCRIPT
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ Which of the following is a recommended USB keyboard mitigation for
sites requiring high security?A) Disable USB ports in the system.B) Restrict
USB devices with approved PIDs and VIDs.C) Block the USB devices
physically.D) Restrict USB devices with approved user accounts..
Answer: C) Block the USB devices physically.
◍ SEC401.
Answer: Security Essentials: Network, Endpoint, and Cloud - GIAC
Security Essentials (GSEC)
◍ Which of the following Cisco IOS commands is used to shut the port down
automatically when the maximum number of MAC addresses is
exceeded?A) switchport port-security violation shutdownB) switchport
port-security limit rate source-mac-shutdownC) switchport port-security
violation auto-shutdownD) switchport port-security
mac-exceed-port-shutdown.
Answer: A) switchport port-security violation shutdown
◍ What is a common failing associated with focusing only on
compliance-drive security?A) Compliance-driven security tends to focus
only on hardening internal systems.B) Compliance-driven security tends to
focus only on hardening the perimeter.C) Compliance-driven security tends
to be costly in terms of solutions and resources.D) Compliance-driven
security tends to fail in the face of a persistent adversary..
Answer: D) Compliance-driven security tends to fail in the face of a
persistent adversary.
,◍ SEC504.
Answer: Hacker Tools, Techniques, and Incident Handling - GIAC Certified
Incident Handler (GCIH)
◍ Which of the following is described by Lockheed Martin as a
countermeasure action to the Kill Chain?A) DisruptB) PreventC) ReactD)
Remove.
Answer: A) Disrupt
◍ SEC503.
Answer: Intrusion Detection In-Depth - GIAC Certified Intrusion Analyst
(GCIA)
◍ What is an easy to implement and effective control an organization can
leverage to make pivoting more difficult for an attacker?A) WPA2B) P2P
patchingC) Private VLAND) VPN.
Answer: C) Private VLAN
◍ Which type of private VLAN ports may only communicate with
promiscuous ports?A) IsolatedB) PromiscuousC) NetworkD) Community.
Answer: A) Isolated
◍ SEC511.
Answer: Continuous Monitoring and Security Operations - GIAC
Continuous Monitoring Certification (GMON)
◍ SEC450.
Answer: Blue Team Fundamentals: Security Operations and Analysis -
GIAC Security Operations Certified (GSOC)
◍ Which of the following wireless standards supports up to 1300 Mbps?A)
802.11bB) 802.11acC) 802.11nD) 802.11w.
Answer: B) 802.11ac
◍ In which phase of the security architecture design lifecycle is threat
modeling and attack surface analysis conducted?A) ScanB) Discover and
AssessC) PlanD) Design.
, Answer: C) Plan
◍ SEC487.
Answer: Open-Source Intelligence (OSINT) Gathering and Analysis - GIAC
Open Source Intelligence (GOSI)
◍ Which of the following is the best practice to mitigate against the Cisco
Discovery Protocol (CDP) information leakage attack?A) Disable the CDP
unless expressly required.B) No mitigations are needed since CDP is secure
by default.C) Schedule the CDP patch regularly.D) Enable the SECDP
feature in the CDP to secure the CD
P. .
Answer: A) Disable the CDP unless expressly required.
◍ Which of the following prevents physical access to the network when
plugging in an unauthorized device?A) MAC address filteringB) Packet
filtering firewallC) Background checksD) Two-factor authentication.
Answer: A) MAC address filtering
◍ What would be one of the first steps for a security architect when building
or redesigning a security architecture to secure an organization?A) Remove
unnecessary egress trafficB) Perform a perimeter pen testC) Deploy patches
to external systemsD) Identify critical assets.
Answer: D) Identify critical assets
◍ SEC501.
Answer: Advanced Security Essentials - Enterprise Defender - GIAC
Certified Enterprise Defender (GCED)
◍ SEC505.
Answer: Securing Windows and PowerShell Automation - GIAC Certified
Windows Security Administrator (GCWN)
◍ Which of the following is a method of detecting a BYOAP problem on a
network?A) Multiple VPN connections from the internal network.B)
Multiple URL requests from the same source I
P. C) Multiple SSIDs in the area.D) Multiple user agent strings from the
, same IP address..
Answer: D) Multiple user agent strings from the same IP address.
◍ SEC555.
Answer: SIEM with Tactical Analytics - GIAC Certified Detection Analyst
(GCDA)
◍ What could be implemented to mitigate the risk of one client pivoting to
another on the same network?A) Host-based antipivotB) Next-gen
antivirusC) NAC controlsD) Private VLANs.
Answer: D) Private VLANs
◍ What is the term used for when the red team is working together with the
blue team through simulation of specific threat scenarios?A) Purple
teamingB) Black-hat teamingC) Defensive teamingD) Multi-front teaming.
Answer: A) Purple teaming
◍ SEC488.
Answer: Cloud Security Essentials - GIAC Cloud Security Essentials
(GCLD)
◍ SEC510.
Answer: Public Cloud Security: AWS, Azure, and GCP - GIAC Public
Cloud Security (GPCS)
◍ When discussing Prevention (P), Detection (D), and Response (R) in a
time-based security model, which of the following must be true to achieve a
possible effective security?A) P<D+RB) P=D+RC) P>D+RD) P=D=R.
Answer: C) P>D+R
◍ Which of the following is known as a Rubber Ducky?A) USB keyboardB)
Respberry Pi deviceC) Trojan horse executableD) Rogue AP.
Answer: A) USB keyboard
◍ SEC522.
Answer: Application Security: Securing Web Apps, APIs, and
Microservices - GIAC Certified Web Application Defender (GWEB)
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ Which of the following is a recommended USB keyboard mitigation for
sites requiring high security?A) Disable USB ports in the system.B) Restrict
USB devices with approved PIDs and VIDs.C) Block the USB devices
physically.D) Restrict USB devices with approved user accounts..
Answer: C) Block the USB devices physically.
◍ SEC401.
Answer: Security Essentials: Network, Endpoint, and Cloud - GIAC
Security Essentials (GSEC)
◍ Which of the following Cisco IOS commands is used to shut the port down
automatically when the maximum number of MAC addresses is
exceeded?A) switchport port-security violation shutdownB) switchport
port-security limit rate source-mac-shutdownC) switchport port-security
violation auto-shutdownD) switchport port-security
mac-exceed-port-shutdown.
Answer: A) switchport port-security violation shutdown
◍ What is a common failing associated with focusing only on
compliance-drive security?A) Compliance-driven security tends to focus
only on hardening internal systems.B) Compliance-driven security tends to
focus only on hardening the perimeter.C) Compliance-driven security tends
to be costly in terms of solutions and resources.D) Compliance-driven
security tends to fail in the face of a persistent adversary..
Answer: D) Compliance-driven security tends to fail in the face of a
persistent adversary.
,◍ SEC504.
Answer: Hacker Tools, Techniques, and Incident Handling - GIAC Certified
Incident Handler (GCIH)
◍ Which of the following is described by Lockheed Martin as a
countermeasure action to the Kill Chain?A) DisruptB) PreventC) ReactD)
Remove.
Answer: A) Disrupt
◍ SEC503.
Answer: Intrusion Detection In-Depth - GIAC Certified Intrusion Analyst
(GCIA)
◍ What is an easy to implement and effective control an organization can
leverage to make pivoting more difficult for an attacker?A) WPA2B) P2P
patchingC) Private VLAND) VPN.
Answer: C) Private VLAN
◍ Which type of private VLAN ports may only communicate with
promiscuous ports?A) IsolatedB) PromiscuousC) NetworkD) Community.
Answer: A) Isolated
◍ SEC511.
Answer: Continuous Monitoring and Security Operations - GIAC
Continuous Monitoring Certification (GMON)
◍ SEC450.
Answer: Blue Team Fundamentals: Security Operations and Analysis -
GIAC Security Operations Certified (GSOC)
◍ Which of the following wireless standards supports up to 1300 Mbps?A)
802.11bB) 802.11acC) 802.11nD) 802.11w.
Answer: B) 802.11ac
◍ In which phase of the security architecture design lifecycle is threat
modeling and attack surface analysis conducted?A) ScanB) Discover and
AssessC) PlanD) Design.
, Answer: C) Plan
◍ SEC487.
Answer: Open-Source Intelligence (OSINT) Gathering and Analysis - GIAC
Open Source Intelligence (GOSI)
◍ Which of the following is the best practice to mitigate against the Cisco
Discovery Protocol (CDP) information leakage attack?A) Disable the CDP
unless expressly required.B) No mitigations are needed since CDP is secure
by default.C) Schedule the CDP patch regularly.D) Enable the SECDP
feature in the CDP to secure the CD
P. .
Answer: A) Disable the CDP unless expressly required.
◍ Which of the following prevents physical access to the network when
plugging in an unauthorized device?A) MAC address filteringB) Packet
filtering firewallC) Background checksD) Two-factor authentication.
Answer: A) MAC address filtering
◍ What would be one of the first steps for a security architect when building
or redesigning a security architecture to secure an organization?A) Remove
unnecessary egress trafficB) Perform a perimeter pen testC) Deploy patches
to external systemsD) Identify critical assets.
Answer: D) Identify critical assets
◍ SEC501.
Answer: Advanced Security Essentials - Enterprise Defender - GIAC
Certified Enterprise Defender (GCED)
◍ SEC505.
Answer: Securing Windows and PowerShell Automation - GIAC Certified
Windows Security Administrator (GCWN)
◍ Which of the following is a method of detecting a BYOAP problem on a
network?A) Multiple VPN connections from the internal network.B)
Multiple URL requests from the same source I
P. C) Multiple SSIDs in the area.D) Multiple user agent strings from the
, same IP address..
Answer: D) Multiple user agent strings from the same IP address.
◍ SEC555.
Answer: SIEM with Tactical Analytics - GIAC Certified Detection Analyst
(GCDA)
◍ What could be implemented to mitigate the risk of one client pivoting to
another on the same network?A) Host-based antipivotB) Next-gen
antivirusC) NAC controlsD) Private VLANs.
Answer: D) Private VLANs
◍ What is the term used for when the red team is working together with the
blue team through simulation of specific threat scenarios?A) Purple
teamingB) Black-hat teamingC) Defensive teamingD) Multi-front teaming.
Answer: A) Purple teaming
◍ SEC488.
Answer: Cloud Security Essentials - GIAC Cloud Security Essentials
(GCLD)
◍ SEC510.
Answer: Public Cloud Security: AWS, Azure, and GCP - GIAC Public
Cloud Security (GPCS)
◍ When discussing Prevention (P), Detection (D), and Response (R) in a
time-based security model, which of the following must be true to achieve a
possible effective security?A) P<D+RB) P=D+RC) P>D+RD) P=D=R.
Answer: C) P>D+R
◍ Which of the following is known as a Rubber Ducky?A) USB keyboardB)
Respberry Pi deviceC) Trojan horse executableD) Rogue AP.
Answer: A) USB keyboard
◍ SEC522.
Answer: Application Security: Securing Web Apps, APIs, and
Microservices - GIAC Certified Web Application Defender (GWEB)