SANS SEC401 (GSEC) 2026: The
Definitive -Question Practice Exam
with Complete Solutions &
Rationales/Instant Download pdf
SECTION 1: NETWORK ARCHITECTURE & DESIGN (Q1–Q20)
Q1: What is Information Security?
Answer: The practice of protecting information by mitigating information
risks and vulnerabilities.
Rationale: Information security (InfoSec) focuses on preserving the
confidentiality, integrity, and availability (CIA) of information assets through
risk mitigation strategies.
Q2: What does TTP stand for in cybersecurity?
Answer: Tactics, Techniques, Procedures.
Rationale: TTPs describe how threat actors operate. Tactics are high-level
descriptions of adversary behavior, techniques are specific methods used,
and procedures are detailed step-by-step implementations.
,Q3: What is the Risk Management Framework (RMF)?
Answer: A structured process that integrates security and risk management
activities into the system development life cycle.
Rationale: RMF provides a disciplined approach for managing security and
privacy risks, ensuring security is built into systems from inception rather
than bolted on later.
Q4: What is Threat Modeling?
Answer: A process used to identify, assess, and prioritize potential threats
to a system.
Rationale: Threat modeling helps organizations understand their attack
surface and prioritize defenses against the most likely and impactful
threats.
Q5: What is a Vulnerability Assessment?
Answer: The systematic examination of an information system to
determine its security weaknesses.
Rationale: Vulnerability assessments identify, quantify, and prioritize
vulnerabilities in systems, providing a foundation for remediation efforts.
,Q6: What is Incident Response?
Answer: The approach taken to prepare for, detect, contain, and recover
from a security incident.
Rationale: Incident Response (IR) is a structured methodology for
managing security breaches, minimizing damage, and restoring normal
operations.
Q7: What are the three main threat agent categories?
Answer: Opportunistic, Organized cybercrime, and Advanced Persistent
Threats (nation states).
Rationale: Threat agents range from low-skill opportunistic attackers to
highly sophisticated state-sponsored groups, each requiring different
defensive approaches.
Q8: What is Defense in Depth?
Answer: A security strategy that employs multiple layers of defense to
protect information and resources.
Rationale: Also called layered security, Defense in Depth ensures that if
one security control fails, others remain to protect the system.
Q9: What is Communication Flow in network architecture?
Answer: Understanding who accesses data, when data is accessed, and
, how much data is accessed, leading to the development of a baseline
where normal activity allows abnormal activity to stand out.
Rationale: Establishing normal communication patterns enables effective
anomaly detection. This is not a one-time activity but requires continual
updating.
Q10: What are the five examples of attacks against routers?
Answer: Denial of Service, Distributed Denial of Service, Packet Sniffing,
Packet Misrouting, Routing Table Poisoning.
Rationale: Routers are critical infrastructure; each attack type exploits
different vulnerabilities in routing protocols or router configurations.
Q11: What are the benefits of understanding network architecture?
Answer: Situational awareness, prioritization of effort, reduced cost of
effort, timely detection of attacks, and timely detection = timely response =
reduction of damage.
Rationale: Understanding network architecture provides context for
security decisions, enabling more efficient resource allocation and faster
incident response.
Q12: What are the three network design objectives?
Answer: Protect internal network from external attacks, provide defense in
Definitive -Question Practice Exam
with Complete Solutions &
Rationales/Instant Download pdf
SECTION 1: NETWORK ARCHITECTURE & DESIGN (Q1–Q20)
Q1: What is Information Security?
Answer: The practice of protecting information by mitigating information
risks and vulnerabilities.
Rationale: Information security (InfoSec) focuses on preserving the
confidentiality, integrity, and availability (CIA) of information assets through
risk mitigation strategies.
Q2: What does TTP stand for in cybersecurity?
Answer: Tactics, Techniques, Procedures.
Rationale: TTPs describe how threat actors operate. Tactics are high-level
descriptions of adversary behavior, techniques are specific methods used,
and procedures are detailed step-by-step implementations.
,Q3: What is the Risk Management Framework (RMF)?
Answer: A structured process that integrates security and risk management
activities into the system development life cycle.
Rationale: RMF provides a disciplined approach for managing security and
privacy risks, ensuring security is built into systems from inception rather
than bolted on later.
Q4: What is Threat Modeling?
Answer: A process used to identify, assess, and prioritize potential threats
to a system.
Rationale: Threat modeling helps organizations understand their attack
surface and prioritize defenses against the most likely and impactful
threats.
Q5: What is a Vulnerability Assessment?
Answer: The systematic examination of an information system to
determine its security weaknesses.
Rationale: Vulnerability assessments identify, quantify, and prioritize
vulnerabilities in systems, providing a foundation for remediation efforts.
,Q6: What is Incident Response?
Answer: The approach taken to prepare for, detect, contain, and recover
from a security incident.
Rationale: Incident Response (IR) is a structured methodology for
managing security breaches, minimizing damage, and restoring normal
operations.
Q7: What are the three main threat agent categories?
Answer: Opportunistic, Organized cybercrime, and Advanced Persistent
Threats (nation states).
Rationale: Threat agents range from low-skill opportunistic attackers to
highly sophisticated state-sponsored groups, each requiring different
defensive approaches.
Q8: What is Defense in Depth?
Answer: A security strategy that employs multiple layers of defense to
protect information and resources.
Rationale: Also called layered security, Defense in Depth ensures that if
one security control fails, others remain to protect the system.
Q9: What is Communication Flow in network architecture?
Answer: Understanding who accesses data, when data is accessed, and
, how much data is accessed, leading to the development of a baseline
where normal activity allows abnormal activity to stand out.
Rationale: Establishing normal communication patterns enables effective
anomaly detection. This is not a one-time activity but requires continual
updating.
Q10: What are the five examples of attacks against routers?
Answer: Denial of Service, Distributed Denial of Service, Packet Sniffing,
Packet Misrouting, Routing Table Poisoning.
Rationale: Routers are critical infrastructure; each attack type exploits
different vulnerabilities in routing protocols or router configurations.
Q11: What are the benefits of understanding network architecture?
Answer: Situational awareness, prioritization of effort, reduced cost of
effort, timely detection of attacks, and timely detection = timely response =
reduction of damage.
Rationale: Understanding network architecture provides context for
security decisions, enabling more efficient resource allocation and faster
incident response.
Q12: What are the three network design objectives?
Answer: Protect internal network from external attacks, provide defense in