SANS 515 UPDATED FINAL STUDY PAPER 2026
COMPLETE QUESTIONS AND ANSWERS
◉ Traffic Light Protocol. Answer: 1. TLP Red: Named recipients only
2. TLP Amber: Limited distribution on need-to-know basis
3. TLP Green: Community wide distribution; you define community
4. TLP White: No restrictions and can be posted online
◉ Threat Pool. Answer: Sunny Side up Egg of Doom slide:
ICS Capable Threat Actor Pool in the middle. Branching to the right
showing IT Attacks that can impact ICS with actors, tools, and skills
increasing
◉ The Information Attack Space. Answer: 1. Information attack
space is the opportunity in the threat category
2. Common aspects for ICS include:
1. Publicly searchable information such as new projects and
mergers
2. Internet-connected control systems
3. Users posting externally on social media and job sites
3. Reducing the information attack space helps drive how security
must be done at the organization
,◉ Sources of Open Source Information. Answer: 1. Public Relations
Documents
2. Partnership Announcements
3. Company Information
4. Job Descriptions
5. Advisories and Alerts
6. Internet-Connected Devices
7. Exploit Databases
8. User Forums
◉ MIC P&ID. Answer: Piping and Instrumentation diagram view
◉ Importance of ICS Asset Identification. Answer: 1. Hard to defend
what you do not know you have
2. Advanced security solutions are most effective on top of
fundamental security
3. Threat Intelligence Consumption, NSM, and Incident Response
requires network knowledge
4. Non-security use cases such as asset management, failing devices,
investigations for outages
, ◉ Asset Identification on a Limited Budget. Answer: Identifying
assets and documentation them does not have to cost money: Paid
products usually add ease, but it is possible with open source or
native tools.
Four Examples:
1. Physical Inspection: time consuming and difficult in large
environments
2. Traffic Analysis: Packet capture analysis safer for ICS
environments
3. Configuration File Analysis: Great approach to map known assets
4. Scanning: Fast recommended only when in process outage or
when tuned with assistance of ICS supplier.
◉ Approach to Building a CMF. Answer: 1. Develop New
Requirements
2. Develop A Collection Plan
3. Implement
4. Test
5. Update Collection Plan
◉ A CMF Security Controls as a Collection Profile. Answer: 1. CMFs
can be used as a collection package requirement and paired with
security controls that provide collection as a standard profile across
the organization
COMPLETE QUESTIONS AND ANSWERS
◉ Traffic Light Protocol. Answer: 1. TLP Red: Named recipients only
2. TLP Amber: Limited distribution on need-to-know basis
3. TLP Green: Community wide distribution; you define community
4. TLP White: No restrictions and can be posted online
◉ Threat Pool. Answer: Sunny Side up Egg of Doom slide:
ICS Capable Threat Actor Pool in the middle. Branching to the right
showing IT Attacks that can impact ICS with actors, tools, and skills
increasing
◉ The Information Attack Space. Answer: 1. Information attack
space is the opportunity in the threat category
2. Common aspects for ICS include:
1. Publicly searchable information such as new projects and
mergers
2. Internet-connected control systems
3. Users posting externally on social media and job sites
3. Reducing the information attack space helps drive how security
must be done at the organization
,◉ Sources of Open Source Information. Answer: 1. Public Relations
Documents
2. Partnership Announcements
3. Company Information
4. Job Descriptions
5. Advisories and Alerts
6. Internet-Connected Devices
7. Exploit Databases
8. User Forums
◉ MIC P&ID. Answer: Piping and Instrumentation diagram view
◉ Importance of ICS Asset Identification. Answer: 1. Hard to defend
what you do not know you have
2. Advanced security solutions are most effective on top of
fundamental security
3. Threat Intelligence Consumption, NSM, and Incident Response
requires network knowledge
4. Non-security use cases such as asset management, failing devices,
investigations for outages
, ◉ Asset Identification on a Limited Budget. Answer: Identifying
assets and documentation them does not have to cost money: Paid
products usually add ease, but it is possible with open source or
native tools.
Four Examples:
1. Physical Inspection: time consuming and difficult in large
environments
2. Traffic Analysis: Packet capture analysis safer for ICS
environments
3. Configuration File Analysis: Great approach to map known assets
4. Scanning: Fast recommended only when in process outage or
when tuned with assistance of ICS supplier.
◉ Approach to Building a CMF. Answer: 1. Develop New
Requirements
2. Develop A Collection Plan
3. Implement
4. Test
5. Update Collection Plan
◉ A CMF Security Controls as a Collection Profile. Answer: 1. CMFs
can be used as a collection package requirement and paired with
security controls that provide collection as a standard profile across
the organization