SANS SEC401 MODULE QUIZZES
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
>> Security operations
Answer: Day-to-day security monitoring and incident response activities
>> SOC
Answer: Security Operations Center — team monitoring and responding to
security events
>> SIEM
Answer: Security Information and Event Management — aggregates and
correlates logs
>> Log management
Answer: Collecting, storing, and analyzing logs from all systems
>> Centralized logging
Answer: Sending all logs to single platform — essential for correlation
>> Log retention
Answer: How long logs are kept — compliance and forensics requirements
>> Event correlation
Answer: Identifying relationships between events from different sources
>> Alert triage
, Answer: Evaluating alerts to determine if they represent real threats
>> False positive
Answer: Alert triggered by benign activity — wastes analyst time
>> False negative
Answer: Real attack not triggering an alert — most dangerous miss
>> True positive
Answer: Alert correctly identifying a real attack
>> True negative
Answer: Correctly identifying benign activity — no alert generated
>> Alert fatigue
Answer: Analysts overwhelmed by volume of alerts — misses increase
>> Baseline
Answer: Normal behavior profile — deviations trigger investigation
>> Behavioral analytics
Answer: Detecting anomalies in user and entity behavior — UEBA
>> UEBA
Answer: User and Entity Behavior Analytics — detects insider threats and
compromised accounts
>> Threat hunting
Answer: Proactively searching for threats not caught by automated tools
PRACTICE EXAMINATION 2026
QUESTIONS WITH ANSWERS GRADED A+
>> Security operations
Answer: Day-to-day security monitoring and incident response activities
>> SOC
Answer: Security Operations Center — team monitoring and responding to
security events
>> SIEM
Answer: Security Information and Event Management — aggregates and
correlates logs
>> Log management
Answer: Collecting, storing, and analyzing logs from all systems
>> Centralized logging
Answer: Sending all logs to single platform — essential for correlation
>> Log retention
Answer: How long logs are kept — compliance and forensics requirements
>> Event correlation
Answer: Identifying relationships between events from different sources
>> Alert triage
, Answer: Evaluating alerts to determine if they represent real threats
>> False positive
Answer: Alert triggered by benign activity — wastes analyst time
>> False negative
Answer: Real attack not triggering an alert — most dangerous miss
>> True positive
Answer: Alert correctly identifying a real attack
>> True negative
Answer: Correctly identifying benign activity — no alert generated
>> Alert fatigue
Answer: Analysts overwhelmed by volume of alerts — misses increase
>> Baseline
Answer: Normal behavior profile — deviations trigger investigation
>> Behavioral analytics
Answer: Detecting anomalies in user and entity behavior — UEBA
>> UEBA
Answer: User and Entity Behavior Analytics — detects insider threats and
compromised accounts
>> Threat hunting
Answer: Proactively searching for threats not caught by automated tools