SANS SEC401 MODULE QUIZZES
CERTIFICATION SCRIPT 2026 QUESTIONS
WITH SOLUTIONS GRADED A+
>> Threat landscape
Answer: Range of potential threats facing an organization
>> Threat actor
Answer: Entity posing a threat — nation-state, cybercriminal, insider,
hacktivist
>> Nation-state attacker
Answer: Government-sponsored — highly skilled, well-resourced, persistent
>> Cybercriminal
Answer: Financially motivated attacker — ransomware, fraud, theft
>> Hacktivist
Answer: Politically motivated attacker — disruption and exposure of
perceived wrongdoing
>> Script kiddie
Answer: Unskilled attacker using others' tools — opportunistic targets
>> Insider threat
Answer: Malicious or negligent employee — most difficult to detect
>> APT
, Answer: Advanced Persistent Threat — sophisticated long-term attacker —
nation-state or criminal
>> Attack surface
Answer: All points where attacker can try to enter or extract data
>> Attack vector
Answer: Method or path used to gain unauthorized access
>> Social engineering
Answer: Manipulating people into revealing information or taking actions
>> Phishing
Answer: Fraudulent email appearing legitimate — tricks users into
credentials or malware
>> Spear phishing
Answer: Targeted phishing using personalized information about victim
>> Whaling
Answer: Phishing targeting high-level executives
>> Vishing
Answer: Voice phishing — phone calls impersonating legitimate entities
>> Smishing
Answer: SMS phishing — fraudulent text messages
>> Pretexting
CERTIFICATION SCRIPT 2026 QUESTIONS
WITH SOLUTIONS GRADED A+
>> Threat landscape
Answer: Range of potential threats facing an organization
>> Threat actor
Answer: Entity posing a threat — nation-state, cybercriminal, insider,
hacktivist
>> Nation-state attacker
Answer: Government-sponsored — highly skilled, well-resourced, persistent
>> Cybercriminal
Answer: Financially motivated attacker — ransomware, fraud, theft
>> Hacktivist
Answer: Politically motivated attacker — disruption and exposure of
perceived wrongdoing
>> Script kiddie
Answer: Unskilled attacker using others' tools — opportunistic targets
>> Insider threat
Answer: Malicious or negligent employee — most difficult to detect
>> APT
, Answer: Advanced Persistent Threat — sophisticated long-term attacker —
nation-state or criminal
>> Attack surface
Answer: All points where attacker can try to enter or extract data
>> Attack vector
Answer: Method or path used to gain unauthorized access
>> Social engineering
Answer: Manipulating people into revealing information or taking actions
>> Phishing
Answer: Fraudulent email appearing legitimate — tricks users into
credentials or malware
>> Spear phishing
Answer: Targeted phishing using personalized information about victim
>> Whaling
Answer: Phishing targeting high-level executives
>> Vishing
Answer: Voice phishing — phone calls impersonating legitimate entities
>> Smishing
Answer: SMS phishing — fraudulent text messages
>> Pretexting