- | P a g e
SANS 401 ACTUAL EXAM NEWEST 2025
COMPLETE 200 QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED ANSWERS)
|ALREADY GRADED A+||BRAND NEW
VERSION!!
In which directory can executable programs that are part of the operating system be found?(/) (/var) (/lib) (/dev) (/usr/bin) (/home)
Correct answer: /usr/bin
The Windows Firewall (WF) provides a popup when a new service attempts to listen on your machine. Which of the following should you train users to select from a security perspective if they are unsure of which option to select?(Keep Blocking) (Increase Security Level) (Safe Mode) (Send Request to Administrator)
Correct answer: Keep Blocking
Which Threat will be reduced when avoiding system calls from within a web app?
Correct answer: OS command injection
How often by default does Windows Group Policy check for updated policies?
- | P a g e
(Once a day) (Within 30 minutes of an applied policy change) (Every quarter hour) (Every 90-120 minutes)
Correct answer: Every 90-120 minutes
Which of the following best describes Defense-in-Depth?Layered controls - Separation of duties - Hardened perimeter security - Risk management
Correct answer: Layered controls
Which of the following is considered a recommended practice but not a business requirement?Guideline - Standard - Baseline - Procedure
Correct answer: Guideline
Which of the following is a characteristic of Quality Updates for Windows?Are released less frequently than Feature Updates - Support deferring installation on Home edition devices - Include bug fixes and security patches - Increment the version of Windows
Correct answer: Include bug fixes and security patches
When does applying an encryption algorithm multiple times provide additional security?
- | P a g e
When the algorithm is a group - When the algorithm is not a group - The algorithm uses xor - The algorithm is weak
Correct answer: When the algorithm is not a group
How is a TCP/IP Packet generated as it moves down through the TCP/IP stack?(Network Layer -> Transport Layer -> Internet Layer -> Application Layer ) (Network Layer -> Internet Layer -> Transport Layer -> Application Layer) (Application Layer -> Transport Layer -> Internet Layer -> Network Layer) (Application Layer -> Internet Layer -> Transport Layer -> Network Layer)
Correct answer: Application Layer -> Transport Layer ->
Internet Layer -> Network Layer
Which type of event classification is missed by a NIDS and has the most potential to be a serious event?True positive - False positive - True negative - False negative
Correct answer: False negative
Which access control mechanism requires a high amount of maintenance since all data must be classified, and all users granted appropriate clearance?Mandatory - Role-Based - Ruleset-based - Discretionary
- | P a g e
Correct answer: Mandatory
What is the preferred method of setting up decoy ports on a server?Set up the host to use a very small window size to manage flow control to the ports - Use software which makes ports appear to be open but is not related to the real services - Configure a host- based firewall to respond with RST packets when the decoy port is the destination port - Enable the actual services for the decoy ports and then keep them patched and up to date
Correct answer: Use software which makes ports appear to be
open but is not related to the real services
A system administrator thinks an attacker is sending malicious data to a router. Which tool will help show this?Router configuration guide - Packet sniffer - Remote access tool
- NTP device
Correct answer: Packet sniffer
Which item, when created with default options, is ciphertext?An automobile license plate - An Apple Lossless audio file - A ZIP file - A Windows executable file - A digital signature