Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 19 pages
Exam (elaborations)

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Document preview thumbnail
Preview 3 out of 19 pages

SANS FOR508 PRACTICE EXAMINATION 2026 QUESTIONS WITH ANSWERS GRADED A+

Content preview

SANS FOR508 PRACTICE
EXAMINATION 2026 QUESTIONS
WITH ANSWERS GRADED A+

◍ Dwell Time.
Answer: The time an attacker has remained undetected within a network. An
important metric to track as it directly correlates with the ability of an
attacker to accomplish their objectives.
◍ RegRipper.
Answer: - automated HIVE parser- can parse the following HIVES: SAM,
SECURITY, SYSTEM, SOFTWARE, NTUSER.DAT- also used to parse
restore point registry files
◍ Breakout Time.
Answer: Time is takes an intruder to begin moving laterally once they have
an initial foothold in the network.
◍ What is the first step of incident response?.
Answer: - proper identification of ALL systems compromised- may be
systems compromised with inactive malware
◍ Preparation.
Answer: - establish incident response capability- ensure systems, networks,
applications are sufficiently secure
◍ Identification.
Answer: - the first step toward proper remediation
◍ Containment & Intel Development.
Answer: - identify pivot point - learn lateral movements of adversary-
identify malware- use knowledge to engineer countermeasures *Results in

, Threat Intelligence*
◍ Remediation.
Answer: - actions required over a short period to mitigate current incident
◍ What are the six steps (in order) to ensure comprehensive remediation?.
Answer: (1) Block malicious IP addresses(2) Blackhole malicious domain
names(3) Rebuild compromised systems(4) Coordinate with cloud and
service providers(5) Enterprise password change(6) Verify all remediation
activities
◍ Recovery.
Answer: - move back to day-to-day business- implement long-term
solutions- prevent and detect future incidents
◍ Main Threat Actors.
Answer: APT (Nation State Actors)Organized CrimeHacktivists
◍ NIST.
Answer: US National Institute for Standards and Technology
◍ Follow Up.
Answer: - verify incident is mitigated (additional monitoring)- ensure
adversary is removed (network/host sweeps)- implement additional
countermeasures (audit the network)
◍ Six-Step Incident Response Process.
Answer: 1: Preparation2: Identification3: Containment and Intelligence
Development4: Eradication and Remediation5: Recovery6: Follow-up
◍ Six-Step - Preparation.
Answer: Incident response methodologies emphasize preparation-not only
establishing a response capability so the organization is ready to respond to
incidents but also preventing incidents by ensuring that systems, networks,
and applications are sufficiently secure.
◍ What are the six steps of Incident Response?.
Answer: - Preparation- Identification- Containment and Intel Development-

, Remediation- Recovery- Follow Up
◍ What is one of the key products of the Incident Response team during an
incident?.
Answer: Threat intelligence
◍ Containment Options.
Answer: - enable decoy data sets- bit mangling- adversary network
segmentation- full-scale host/network monitoring- kill switch
◍ Six-Step - Identificatoin.
Answer: Identification is triggered by a suspicious event. This could be from
a security appliance, a call to the help-desk, or the result of something
discovered via threat hunting. Event validation should occur and a decision
made as to the severity of the finding (not valid events lead to a full incident
response). Once an incident response has begun, this phase is used to better
understand the findings and begin scoping the network for additional
compromise.
◍ Intelligence-driven Incident Response.
Answer: - process used to identify actively new compromised systems
◍ Initial Compromise.
Answer: - not usually persistent
◍ Establish foothold/maintain presence.
Answer: - maintained presence despite reboot
◍ Six Step - Containment and Intelligence development.
Answer: In this phase, the goal is to rapidly understand the adversary and
begin crafting a containment strategy. Responders must identify the initial
vulnerability or exploit, how the attackers are maintaining persistence and
laterally moving in the network, and how command and control is being
accomplished. in conjunction with the previous scoping phase, responders
will work to have a complete picture of the attack and often implement
changes to the environment to increase host and network visibility. Threat
intelligence is one of the key products of the IP team during this phase.

Document information

Uploaded on
June 25, 2026
Number of pages
19
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeInsider
4.1
(9)
Sold
123
Followers
2
Items
46210
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions