SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
In what format are Sigma rules written?
A) JSON
B) HTML
C) YAML
D) XML - ANSWERS-C) YAML
What are the *four* components of Sigma rules? - ANSWERS-1)
Metadata
2) Log Source
3) Detection
4) Condition
Which open-source tool can help you identify the ATT&CK techniques
addressed by your organizations existing rulesets?
A) Sigma2attack
B) ElkAttack
END OF
PAGE
1
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
C) Splunk Enterprise
D) YaraAttack - ANSWERS-A) Sigma2attack
What protocol and port does syslog use to send log entries by default?
A) TCP 514
B) TCP 161
C) UDP 161
D) UDP 514 - ANSWERS-D) UDP 514
What is a host-based firewall available in the Linux environment?
A) Zeek
B) Snort
C) iptables
D) tcpdump - ANSWERS-C) iptables
END OF
PAGE
2
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
Which of the following is one of the basic principles of perimeter
security?
A) Internal access is untrusted
B) External access is trusted
C) Internal access is trusted
D) VPN access is untrusted - ANSWERS-A) Internal access is untrusted
Which systems can benefit from auditpol.exe's capability to apply a
standardized audit policy?
A) Network devices
B) Non-Windows systems
C) Domain-joined systems
D) Non-domain-joined systems - ANSWERS-D) Non-domain-joined
systems
Which of the following is the default location for Linux/Unix logs?
END OF
PAGE
3
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
A) /etc/log
B) /log
C) /var/log
D) /log/tmp - ANSWERS-C) /var/log
Detecting insider threat activity in a Windows environment can be
accomplished by monitoring audit logs for which type of activity?
A) Scanning in AV firewall logs
B) ICMP echo requests
C) Vulnerability scanning internally
D) Attempts to enumerate group membership - ANSWERS-D) Attempts
to enumerate group membership
Which of the following default settings on a host-based firewall breaks
the law of zero trust architecture?
END OF
PAGE
4
QUESTIONS AND
ANSWERS 2026 - 2027
In what format are Sigma rules written?
A) JSON
B) HTML
C) YAML
D) XML - ANSWERS-C) YAML
What are the *four* components of Sigma rules? - ANSWERS-1)
Metadata
2) Log Source
3) Detection
4) Condition
Which open-source tool can help you identify the ATT&CK techniques
addressed by your organizations existing rulesets?
A) Sigma2attack
B) ElkAttack
END OF
PAGE
1
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
C) Splunk Enterprise
D) YaraAttack - ANSWERS-A) Sigma2attack
What protocol and port does syslog use to send log entries by default?
A) TCP 514
B) TCP 161
C) UDP 161
D) UDP 514 - ANSWERS-D) UDP 514
What is a host-based firewall available in the Linux environment?
A) Zeek
B) Snort
C) iptables
D) tcpdump - ANSWERS-C) iptables
END OF
PAGE
2
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
Which of the following is one of the basic principles of perimeter
security?
A) Internal access is untrusted
B) External access is trusted
C) Internal access is trusted
D) VPN access is untrusted - ANSWERS-A) Internal access is untrusted
Which systems can benefit from auditpol.exe's capability to apply a
standardized audit policy?
A) Network devices
B) Non-Windows systems
C) Domain-joined systems
D) Non-domain-joined systems - ANSWERS-D) Non-domain-joined
systems
Which of the following is the default location for Linux/Unix logs?
END OF
PAGE
3
, SANS - SEC530 EXAM LATEST
QUESTIONS AND
ANSWERS 2026 - 2027
A) /etc/log
B) /log
C) /var/log
D) /log/tmp - ANSWERS-C) /var/log
Detecting insider threat activity in a Windows environment can be
accomplished by monitoring audit logs for which type of activity?
A) Scanning in AV firewall logs
B) ICMP echo requests
C) Vulnerability scanning internally
D) Attempts to enumerate group membership - ANSWERS-D) Attempts
to enumerate group membership
Which of the following default settings on a host-based firewall breaks
the law of zero trust architecture?
END OF
PAGE
4