SANS FOR508 CERTIFICATION SCRIPT
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ Six-Step Incident Response Process.
Answer: 1. Preparation2. Identification and Scoping3.
Containment/Intelligence Development4. Eradication/Remediation5.
Recovery6. Lessons Learned/ Threat Intel Consumption
◍ Preparation.
Answer: Preparation ensures that the right people from the right teams are
involved, understand their roles, and know what to do when an incident
occurs.
◍ Identification.
Answer: An alert from a security appliance, an escalated event, or something
discovered during threat hunting.
◍ IDS.
Answer: Intrusion Detection System
◍ IPS.
Answer: Intrusion Prevention System
◍ Containment.
Answer: Responder must identify initial vulnerability or exploit, how the
attackers are maintaining persistence and laterally moving in the network,
and how C2 is operating.
◍ Eradication.
Answer: Aims to remove the threat and restore business operations to a
normal state. A full scope of the intrusion must be understood before this
, can take place.
◍ Recovery.
Answer: Recovery leads the enterprise back to day-to-day business
operations. Often divided into near, mid, and long term changes. This should
result in some recovery changes.
◍ Follow-up/ Lessons learned.
Answer: Used to verify the incident has been mitigated and the adversary
was removed. This combines additional monitoring, network sweeps,
looking for new breaches, and auditing the network.
◍ Eradication change examples.
Answer: - Block malicious IP addresses- Blackhole malicious domains-
Rebuild compromised systems- coordinate with cloud and service providers-
enterprise password changes- implement validation
◍ packet and datagram are interchangeable.
Answer: packet and datagram or interchangeable
◍ 4 layers of TCP/IP Model.
Answer: Application (HTTP,SMTP,DNS) - (AppliTransport
(TCP,UDP)Internet (IP)Network Access (IEEE 802.x)
◍ TCP/IP Encapsulation of layers.
Answer: Apes Tickle in nylon or knikersApplication (Application
Payload)Transport (TCP Header)Internet (IP Packetheader)Network Access
(Frame Header)
◍ Recovery change examples.
Answer: - improve enterprise authentication model- enhanced network
visibility- establish comprehensive patch management program- enforce
changes management program- centralized logging (siem)- enhance
password portal- establish security awareness training program- network
redesign
◍ OSI.
, Answer: Open System Interconnection Model
◍ Encapsulation.
Answer: Adding header information as a packet is passed down the TCP/IP
stack (De-encapsulation is the opposite
◍ What is needed to de-encapsulate.
Answer: A knowledge of what follows the currently layer the next layer to
pass to and where is starts or the size of its header
◍ Bit.
Answer: smallest unit 0 or 1
◍ A remediation event should....
Answer: 1. deny access to the environment2. eliminate the ability for the
adversary to react to the remediation3. remove the persistence of the
adversary from the environment4. degrade the ability for the adversary to
return
◍ Nibble.
Answer: 4 bits or one hex
◍ Remediation consists of 3 steps.
Answer: 1. posture for remediation (scoping the entire issue)2. execute
remediation (execute and follow removal plan)3. implement and apply
additional security controls
◍ Critical remediation controls.
Answer: 1. disconnect from the internet2. implement strict network
segmentation (dont allow subnets to communicate with each other)3. block
ip addresses and domains for c24. remove all infected systems5. restrict
access to compromised accounts6. restrict access to compromised domain
admin accounts7. validate that all these steps are done properly
◍ Byte.
Answer: 8bit 2 nibbles or 2 hex
◍ What is digital forensics?.
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ Six-Step Incident Response Process.
Answer: 1. Preparation2. Identification and Scoping3.
Containment/Intelligence Development4. Eradication/Remediation5.
Recovery6. Lessons Learned/ Threat Intel Consumption
◍ Preparation.
Answer: Preparation ensures that the right people from the right teams are
involved, understand their roles, and know what to do when an incident
occurs.
◍ Identification.
Answer: An alert from a security appliance, an escalated event, or something
discovered during threat hunting.
◍ IDS.
Answer: Intrusion Detection System
◍ IPS.
Answer: Intrusion Prevention System
◍ Containment.
Answer: Responder must identify initial vulnerability or exploit, how the
attackers are maintaining persistence and laterally moving in the network,
and how C2 is operating.
◍ Eradication.
Answer: Aims to remove the threat and restore business operations to a
normal state. A full scope of the intrusion must be understood before this
, can take place.
◍ Recovery.
Answer: Recovery leads the enterprise back to day-to-day business
operations. Often divided into near, mid, and long term changes. This should
result in some recovery changes.
◍ Follow-up/ Lessons learned.
Answer: Used to verify the incident has been mitigated and the adversary
was removed. This combines additional monitoring, network sweeps,
looking for new breaches, and auditing the network.
◍ Eradication change examples.
Answer: - Block malicious IP addresses- Blackhole malicious domains-
Rebuild compromised systems- coordinate with cloud and service providers-
enterprise password changes- implement validation
◍ packet and datagram are interchangeable.
Answer: packet and datagram or interchangeable
◍ 4 layers of TCP/IP Model.
Answer: Application (HTTP,SMTP,DNS) - (AppliTransport
(TCP,UDP)Internet (IP)Network Access (IEEE 802.x)
◍ TCP/IP Encapsulation of layers.
Answer: Apes Tickle in nylon or knikersApplication (Application
Payload)Transport (TCP Header)Internet (IP Packetheader)Network Access
(Frame Header)
◍ Recovery change examples.
Answer: - improve enterprise authentication model- enhanced network
visibility- establish comprehensive patch management program- enforce
changes management program- centralized logging (siem)- enhance
password portal- establish security awareness training program- network
redesign
◍ OSI.
, Answer: Open System Interconnection Model
◍ Encapsulation.
Answer: Adding header information as a packet is passed down the TCP/IP
stack (De-encapsulation is the opposite
◍ What is needed to de-encapsulate.
Answer: A knowledge of what follows the currently layer the next layer to
pass to and where is starts or the size of its header
◍ Bit.
Answer: smallest unit 0 or 1
◍ A remediation event should....
Answer: 1. deny access to the environment2. eliminate the ability for the
adversary to react to the remediation3. remove the persistence of the
adversary from the environment4. degrade the ability for the adversary to
return
◍ Nibble.
Answer: 4 bits or one hex
◍ Remediation consists of 3 steps.
Answer: 1. posture for remediation (scoping the entire issue)2. execute
remediation (execute and follow removal plan)3. implement and apply
additional security controls
◍ Critical remediation controls.
Answer: 1. disconnect from the internet2. implement strict network
segmentation (dont allow subnets to communicate with each other)3. block
ip addresses and domains for c24. remove all infected systems5. restrict
access to compromised accounts6. restrict access to compromised domain
admin accounts7. validate that all these steps are done properly
◍ Byte.
Answer: 8bit 2 nibbles or 2 hex
◍ What is digital forensics?.