SANS FOR508 VIEW AHEAD TEST 2026
COMPLETE QUESTIONS AND CORRECT
ANSWERS UPDATED STUDY GUIDE
●● Breakout Time
Answer: Time it takes an attacker to begin moving laterally once
initiated foothold in network.
●● Incident Response Process (Six Steps)
Answer: 1. Preparation. 2. Identification/Scoping. 3.
Containment/Intelligence Development. 4. Eradication/Remediation. 5.
Recovery. 6. Lessons Learned/Threat Intel Consumption.
●● Preparation - Step 1 of IR Process
Answer: Establishing a response capability & preventing incidents by
ensuring systems, networks, & apps sufficiently secure.
●● Identification/Scoping - Step 2 of IR Process
Answer: Triggered by suspicious event. Event validation should occur,
decision made as to severity (not valid events lead to full IR response.
One IR begun, phase used to better understand findings & begin scoping
network for addt'l compromise.
, ●● Containment/Intel Development - Step 3 of IR Process
Answer: Goal to rapidly understand adversary begin crafting
containment strategy. Identify initial exploit, how attackers maintaining
persistence & laterally moving, how C2 being accomplished. Implement
changes to increase host/network visibility. Threat intel key part of
phase.
●● Eradication/Remediation - Step 4 of IR Process
Answer: Arguably most important phase. Aim to remove threat, restore
ops to normal state. Ex. changes to environment: -Block malicious IP
addresses; blackhole malicious domain names; rebuild compromised
systems; coordinate w/cloud & service providers; Enterprise-wide
password changes; implementation validation
●● Recovery - Step 5 of IR Process
Answer: leads enterprise back to day-to-day business. Goal is to improve
overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility;
Establish Comprehensive Patch Mgmt Program; Centralized Logging
(SIEM/SIM); Enhance Password Portal; Establish Security Awareness
Training Program; Network Redesign
●● Follow-Up - Step 6 of IR Process
Answer: Verify incident mitigated, adversary removed, addt'l
countermeasures implemented correctly. Addt'l monitoring, network
COMPLETE QUESTIONS AND CORRECT
ANSWERS UPDATED STUDY GUIDE
●● Breakout Time
Answer: Time it takes an attacker to begin moving laterally once
initiated foothold in network.
●● Incident Response Process (Six Steps)
Answer: 1. Preparation. 2. Identification/Scoping. 3.
Containment/Intelligence Development. 4. Eradication/Remediation. 5.
Recovery. 6. Lessons Learned/Threat Intel Consumption.
●● Preparation - Step 1 of IR Process
Answer: Establishing a response capability & preventing incidents by
ensuring systems, networks, & apps sufficiently secure.
●● Identification/Scoping - Step 2 of IR Process
Answer: Triggered by suspicious event. Event validation should occur,
decision made as to severity (not valid events lead to full IR response.
One IR begun, phase used to better understand findings & begin scoping
network for addt'l compromise.
, ●● Containment/Intel Development - Step 3 of IR Process
Answer: Goal to rapidly understand adversary begin crafting
containment strategy. Identify initial exploit, how attackers maintaining
persistence & laterally moving, how C2 being accomplished. Implement
changes to increase host/network visibility. Threat intel key part of
phase.
●● Eradication/Remediation - Step 4 of IR Process
Answer: Arguably most important phase. Aim to remove threat, restore
ops to normal state. Ex. changes to environment: -Block malicious IP
addresses; blackhole malicious domain names; rebuild compromised
systems; coordinate w/cloud & service providers; Enterprise-wide
password changes; implementation validation
●● Recovery - Step 5 of IR Process
Answer: leads enterprise back to day-to-day business. Goal is to improve
overall security of network & detect/prevent reinfection. Ex. changes:
Improve Enterprise Authentication Model; Enhanced Network Visibility;
Establish Comprehensive Patch Mgmt Program; Centralized Logging
(SIEM/SIM); Enhance Password Portal; Establish Security Awareness
Training Program; Network Redesign
●● Follow-Up - Step 6 of IR Process
Answer: Verify incident mitigated, adversary removed, addt'l
countermeasures implemented correctly. Addt'l monitoring, network