Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

SANS - SEC530 EXAM QUESTION BANK | FREQUENTLY TESTED QUESTIONS WITH CORRECT ANSWERS | BRAND NEW!

Rating
-
Sold
-
Pages
114
Grade
A+
Uploaded on
10-04-2026
Written in
2025/2026

SANS - SEC530 EXAM QUESTION BANK | FREQUENTLY TESTED QUESTIONS WITH CORRECT ANSWERS | BRAND NEW!

Institution
SANS - SEC530
Course
SANS - SEC530

Content preview

Page 1 of 114


SANS - SEC530 EXAM QUESTION BANK |
FREQUENTLY TESTED QUESTIONS WITH
CORRECT ANSWERS | BRAND NEW!



Defensible Security Architecture and Engineering: Implementing
Zero Trust for the Hybrid Enterprise (SANS SEC530)




Which Zeek configuration file determines which network
interface is monitored?


A) $PREFIX/etc/interface.cfg
B) $PREFIX/etc/broctl.cfg
C) $PREFIX/etc/networks.cfg
D) $PREFIX/etc/node.cfg - ✔✔✔ Correct Answer > D)
$PREFIX/etc/node.cfg


In which of the following circumstances would network DLP
likely detect a possible data exfiltration?


A) Encrypted file over an encrypted network protocol

,Page 2 of 114


B) Encrypted file over a cleartext network protocol
C) Network encryption with SSL inspection
D) Application-level compression - ✔✔✔ Correct Answer > C) Network
encryption with SSL inspection


Which of the following controls would be effective at detecting a
malicious executable that was specially crafted to evade
signature-based detection controls?


A) Intrusion prevention
B) Antivirus
C) Malware detonation
D) URL filtering - ✔✔✔ Correct Answer > C) Malware detonation


With aggregate network utilization at monitored choke points
projected at 4 Gbps, how many CPU cores will be required for
traffic analysis with Zeek?


A) 17
B) 4
C) 9
D) 21 - ✔✔✔ Correct Answer > A) 17

,Page 3 of 114


Which of the following describes the malware detonation
workflow?


A) Analyze the AV and reputation databases and detonate only if
the results are positive.
B) Analyze the AV reputation databases and detonate only if the
results are negative.
C) Detonate files only if a static analysis detects use of a packer
and/or high entropy.
D) Detonate all identified executables, documents, and URLs. -
✔✔✔ Correct Answer > A) Analyze the AV and reputation databases
and detonate only if the results are positive.


Which open-source tool is available for blue teamers to assess
organizations' detection and prevention capability against
password guessing from multiple IP addresses that rely on
Amazon EC2 instances?


A) IONCannon
B) BotNetCannon
C) ProxyCannon
D) ProxyBots - ✔✔✔ Correct Answer > C) ProxyCannon

, Page 4 of 114


What is a security consideration when implementing an Always
On VPN solution?


A) It requires a stored password or certificate on each system.
B) It creates a blind spot for centralized security solutions.
C) It only works on a split-tunnel VPN.
D) It uses less bandwidth. - ✔✔✔ Correct Answer > A) It requires a
stored password or certificate on each system.


Which Linux distro is an open-source platform for full-fledged
network security monitoring?


A) Kali
B) Suricata
C) Zeek
D) Security Onion - ✔✔✔ Correct Answer > D) Security Onion


Which configuration option can be used to prevent passive
TLS/SSL decryption?


A) Update all web servers to only support TLS 1.2 and above.
B) Update all web servers to only support elliptic curve-based
ciphers.

Written for

Institution
SANS - SEC530
Course
SANS - SEC530

Document information

Uploaded on
April 10, 2026
Number of pages
114
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$29.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Starshine1 Devry University
Follow You need to be logged in order to follow users or courses
Sold
349
Member since
3 year
Number of followers
124
Documents
5895
Last sold
2 days ago
HIGH SCORE ACHIEVERS

I am dedicated and knowledgeable expert specializing in Health care, Nursing, Mathematics, Psychology, History, Physics and Biology. Simple well-researched education material for you. My work contains updated and latest Exam solutions, Notes and Study guide Correctly 100% verified. Good Luck with your Studies!

3.8

55 reviews

5
25
4
12
3
8
2
1
1
9

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions