SANS 515 FINAL TEST 2026
QUESTIONS WITH CORRECT
ANSWERS GRADED A+
◍ Everyone can do everything they need to do and nothing more. Bradley
Manning - WikiLeaks Target - HVAC hack.
Answer: Principle of Least Privilege
◍ The cornerstone of all security: Everyting done in security addresses one or
more of these three thingsConfidentiality, Integrity,
availabilityConfidentiality - Only those who need to access something can;
ties into principle of least privilegeIntegrity - data is edited correctly and by
the right people. Failure ex.: Delta $5 tickets round trip tickets to anywhere
Delta flies/attach on pricing databaseAvailability - If you cannot use it, why
do you have it?.
Answer: CIA Triad
◍ Pharmaceuticals and government, research.
Answer: Confidentiality
◍ Supply Chain BackDoor.
Answer: Combines 1st Stage Delivery and Exploitation phases
◍ Stuxnet: Host Observables.
Answer: DLL Injection: Lsass.exe, winlogon.exe, svchost.exeRegistry Key
Modification: new registry: mrxnet, 19790509Multiple Files Dropped:
oem7a.pnf, mdmeric3.pnf, mrxnet.sys, mrxcls.syInfected Project File:
S7tgtopx.exeUSB Jumping: USB Loader~WTR4141.tmp, Delete after 3
jumps
◍ Financials maintained in part by confidentiality.
Answer: Integrity
,◍ eCommerce Ex. Amazon make $133,000/per minute thus denial of service
is critical business impact; power company need to keep lights on =
availability issue.
Answer: Availability
◍ Authentication, Authorization, Accountability.
Answer: AAA
◍ Sliding Scale of Cyber Security.
Answer: Architecture, Passive Defense, Active Defense, Intelligence,
Offense
◍ Active Defense Influences.
Answer: Mao Zedong: On Guerrilla WarfareGeneral Depuy: The Army's
FM 100-5Guiding Principles of Mao1. No provocation of the enemy2. No
military bases on foreign soil3. No seizure of enemy land
◍ Detailed steps to make policy happen.
Answer: Procedure
◍ Policy, Procedure and Training.
Answer: PPT
◍ Users must know what policies and procedures say to follow them..
Answer: Training
◍ Broad general statement of management's intent to protect information.
Answer: Policy
◍ Active Cyber Defense Cycle.
Answer: Threat Intelligence Consumption -> Visibility -> Threat Detection
-> Incident Response -> Threat & Environment Manipulation
◍ A security professional needs to be:1/3 technologist1/3 manager1/3
lawyer-Tkhis is the perfect summation of the career field.-Technology
supports security efforts-Management decisions (and budgets) drive
security-Legal issues mandate security requirements.
Answer: Security by Thirds
,◍ WinCC.
Answer: Siemens WinCC SCADA Monitoring was used to sync - easily
detectable on the network
◍ What is intelligence?.
Answer: Both a Product and a Process: Analyzed information about a
competitive entity that fulfills a requirement
◍ Senior Mgmt:-Has legal responsibility to protect the assets of the org:That
give him the ultimate responsibility for security-Authority can be delegated
- responsibility cannot beData owner - person or office with primary
responsibility for data; owners determine classification, protective measures
and moreData custodian - the person/group that implement the controls;
make the decisions of the owner happensUsers - use data; are also
automatically data custodians.
Answer: Security Roles and Responsiblities
◍ safety of people.
Answer: Number 1 Goal of Security
◍ Intelligence Life Cycle.
Answer: 1. Planning and Direction2. Collection3. Process and Exploitation4.
Analysis and Production5. Dissemination and Integration6. Evaluation and
Feedback
◍ years ago: teenagerstoday: we face organized crime and nation states-well
funded-highly motivateddisgruntled insider: difficult to counter; tends to be
subtle; often damaging or even devastatingAccidental insider: common; also
tend to be subtle; in aggregate - even ore damagingOutsider threat source -
inside threat actor: a growing proble, the current most-common attack
vector2014 - 47% of
U. S. adults had private data compromised in a breach (NBC News)FBI can
prove it was North Korea that attacked Sony.
Answer: Nature of the Threat
◍ verify identity; is Keith really Keith?(1) Verifying the integrity of a
, transmitted message. See message integrity, e-mail authentication and MA
C. (2) Verifying the identity of a user logging into a network. Passwords,
digital certificates, smart cards and biometrics can be used to prove the
identity of the client to the network. Passwords and digital certificates can
also be used to identify the network to the client. The latter is important in
wireless networks to ensure that the desired network is being accessed. See
identity management, identity metasystem, OpenID, human authentication,
challenge/response, two-factor authentication, password, digital signature,
IP spoofing, biometrics and CAPTCH
A. Four Levels of ProofThere are four levels of proof that people are indeed
who they say they are. None of them are entirely foolproof, but in order of
least to most secure, they are:1 - What You KnowPasswords are widely used
to identify a user, but only verify that somebody knows the password.2 -
What You HaveDigital certificates in the user's computer add more security
than a password, and smart cards verify that users have a physical token in
their possession, but both laptops and smart cards can be stolen.3 - What
You AreBiometrics such as fingerprints and iris recognition are more
difficult to forge, but you have seen such systems fooled in the movies all
the time!4 - What You DoDynamic biometrics such as hand writing a
signature and voice recognition are the most secure; however, replay attacks
can fool the system..
Answer: Authentication
◍ Control what they are allowed to do. Although we know Keith is Keith,
what can Keith do?.
Answer: Authorization
◍ Harden, patch & monitor.
Answer: HPM
◍ Field of View Bias.
Answer: Operational Environment (location of collection) and Intelligence
Requirements yield a "field of view".
◍ What is a threat?.
QUESTIONS WITH CORRECT
ANSWERS GRADED A+
◍ Everyone can do everything they need to do and nothing more. Bradley
Manning - WikiLeaks Target - HVAC hack.
Answer: Principle of Least Privilege
◍ The cornerstone of all security: Everyting done in security addresses one or
more of these three thingsConfidentiality, Integrity,
availabilityConfidentiality - Only those who need to access something can;
ties into principle of least privilegeIntegrity - data is edited correctly and by
the right people. Failure ex.: Delta $5 tickets round trip tickets to anywhere
Delta flies/attach on pricing databaseAvailability - If you cannot use it, why
do you have it?.
Answer: CIA Triad
◍ Pharmaceuticals and government, research.
Answer: Confidentiality
◍ Supply Chain BackDoor.
Answer: Combines 1st Stage Delivery and Exploitation phases
◍ Stuxnet: Host Observables.
Answer: DLL Injection: Lsass.exe, winlogon.exe, svchost.exeRegistry Key
Modification: new registry: mrxnet, 19790509Multiple Files Dropped:
oem7a.pnf, mdmeric3.pnf, mrxnet.sys, mrxcls.syInfected Project File:
S7tgtopx.exeUSB Jumping: USB Loader~WTR4141.tmp, Delete after 3
jumps
◍ Financials maintained in part by confidentiality.
Answer: Integrity
,◍ eCommerce Ex. Amazon make $133,000/per minute thus denial of service
is critical business impact; power company need to keep lights on =
availability issue.
Answer: Availability
◍ Authentication, Authorization, Accountability.
Answer: AAA
◍ Sliding Scale of Cyber Security.
Answer: Architecture, Passive Defense, Active Defense, Intelligence,
Offense
◍ Active Defense Influences.
Answer: Mao Zedong: On Guerrilla WarfareGeneral Depuy: The Army's
FM 100-5Guiding Principles of Mao1. No provocation of the enemy2. No
military bases on foreign soil3. No seizure of enemy land
◍ Detailed steps to make policy happen.
Answer: Procedure
◍ Policy, Procedure and Training.
Answer: PPT
◍ Users must know what policies and procedures say to follow them..
Answer: Training
◍ Broad general statement of management's intent to protect information.
Answer: Policy
◍ Active Cyber Defense Cycle.
Answer: Threat Intelligence Consumption -> Visibility -> Threat Detection
-> Incident Response -> Threat & Environment Manipulation
◍ A security professional needs to be:1/3 technologist1/3 manager1/3
lawyer-Tkhis is the perfect summation of the career field.-Technology
supports security efforts-Management decisions (and budgets) drive
security-Legal issues mandate security requirements.
Answer: Security by Thirds
,◍ WinCC.
Answer: Siemens WinCC SCADA Monitoring was used to sync - easily
detectable on the network
◍ What is intelligence?.
Answer: Both a Product and a Process: Analyzed information about a
competitive entity that fulfills a requirement
◍ Senior Mgmt:-Has legal responsibility to protect the assets of the org:That
give him the ultimate responsibility for security-Authority can be delegated
- responsibility cannot beData owner - person or office with primary
responsibility for data; owners determine classification, protective measures
and moreData custodian - the person/group that implement the controls;
make the decisions of the owner happensUsers - use data; are also
automatically data custodians.
Answer: Security Roles and Responsiblities
◍ safety of people.
Answer: Number 1 Goal of Security
◍ Intelligence Life Cycle.
Answer: 1. Planning and Direction2. Collection3. Process and Exploitation4.
Analysis and Production5. Dissemination and Integration6. Evaluation and
Feedback
◍ years ago: teenagerstoday: we face organized crime and nation states-well
funded-highly motivateddisgruntled insider: difficult to counter; tends to be
subtle; often damaging or even devastatingAccidental insider: common; also
tend to be subtle; in aggregate - even ore damagingOutsider threat source -
inside threat actor: a growing proble, the current most-common attack
vector2014 - 47% of
U. S. adults had private data compromised in a breach (NBC News)FBI can
prove it was North Korea that attacked Sony.
Answer: Nature of the Threat
◍ verify identity; is Keith really Keith?(1) Verifying the integrity of a
, transmitted message. See message integrity, e-mail authentication and MA
C. (2) Verifying the identity of a user logging into a network. Passwords,
digital certificates, smart cards and biometrics can be used to prove the
identity of the client to the network. Passwords and digital certificates can
also be used to identify the network to the client. The latter is important in
wireless networks to ensure that the desired network is being accessed. See
identity management, identity metasystem, OpenID, human authentication,
challenge/response, two-factor authentication, password, digital signature,
IP spoofing, biometrics and CAPTCH
A. Four Levels of ProofThere are four levels of proof that people are indeed
who they say they are. None of them are entirely foolproof, but in order of
least to most secure, they are:1 - What You KnowPasswords are widely used
to identify a user, but only verify that somebody knows the password.2 -
What You HaveDigital certificates in the user's computer add more security
than a password, and smart cards verify that users have a physical token in
their possession, but both laptops and smart cards can be stolen.3 - What
You AreBiometrics such as fingerprints and iris recognition are more
difficult to forge, but you have seen such systems fooled in the movies all
the time!4 - What You DoDynamic biometrics such as hand writing a
signature and voice recognition are the most secure; however, replay attacks
can fool the system..
Answer: Authentication
◍ Control what they are allowed to do. Although we know Keith is Keith,
what can Keith do?.
Answer: Authorization
◍ Harden, patch & monitor.
Answer: HPM
◍ Field of View Bias.
Answer: Operational Environment (location of collection) and Intelligence
Requirements yield a "field of view".
◍ What is a threat?.