Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

SANS SEC530 EXAM STUDY GUIDE 2026/2027 COMPLETE QUESTIONS WITH VERIFIED CORRECT ANSWERS || 100% GUARANTEED PASS NEWEST VERSION

Rating
-
Sold
-
Pages
106
Grade
A+
Uploaded on
21-04-2026
Written in
2025/2026

SANS SEC530 EXAM STUDY GUIDE 2026/2027 COMPLETE QUESTIONS WITH VERIFIED CORRECT ANSWERS || 100% GUARANTEED PASS NEWEST VERSION 1. Which of the following is a recommended USB keyboard mitigation for sites requiring high security? A) Disable USB ports in the system. B) Restrict USB devices with approved PIDs and VIDs. C) Block the USB devices physically. D) Restrict USB devices with approved user accounts. - ANSWER C) Block the USB devices physically. 2. Which of the following Cisco IOS commands is used to shut the port down automatically when the maximum number of MAC addresses is exceeded? A) switchport port-security violation shutdown B) switchport port-security limit rate source-mac-shutdown C) switchport port-security violation auto-shutdown D) switchport port-security mac-exceed-port-shutdown - ANSWER A) switchport port-security violation shutdown 3. What does DAI stand for, and what does it do? - ANSWER Dynamic ARP Inspection (DAI) prevents ARP spoofing at the switch level, by checking a database of bindings before forwarding an ARP response. 4. How does DHCP starvation work? - ANSWER A malicious system attempts to request all available DHCP addresses in the pool. 5. What is the best way to mitigate DHCP starvation attacks? - ANSWER Most DHCP servers do not have a built-in defense for this type of attack. A *switch* must be configured to stop this type of attack. 6. What type of attack tends to follow a DHCP starvation attack? - ANSWER A rouge DHCP server attack. 7. What is the name of the Windows 10 P2P software update setting? - ANSWER Delivery Optimization 8. What is the more secure alternative to Windows 10 delivery optimization? - ANSWER *WSUS* Windows Server Update Services 9. What are the *three* types of VLAN ports? - ANSWER 1) Promiscuous 2) Isolated 3) Community 10. T/F: A system on the primary VLAN can also be part of a secondary VLAN, such as isolated or community VLANS. - ANSWER True. 11. What type of information is available via NetFlow version 9 logs? - ANSWER 1) Byte and packet count 2) Protocol 3) Source and destination IP address 4) IP and TCP flags 5) TCP and UDP ports 6) ICMP types and codes 7) Interface 8) BGP information and more... 12. SOC Zones - ANSWER Easy containment of the various needs throughout the business such as OT/ICS, Manufacturing, R&D, PCI Zones, business critical applications, cloud critical hosting, and DMZ 13. Time Based Security - ANSWER How long protection works, and how long it takes to detect and react. P D + R 14. Cyber Killchain Countermeasures - ANSWER Detect, Deny, Disrupt, Degrade, Decieve 15. Breakout Point - ANSWER The point in which lateral movement first occurs, signaling the time in which the attack moves to more computers and becomes exponentially more dangerous. 16. OODA Loop - ANSWER Observe. Orient. Decide. Act. A teaching tool originating from military training that promotes the use of a constant cycle of learning; in digital marketing, used to instill the use of hypothesizing, experimentation, data capture and measurement, and then re-stating a new revised hypothesis based on information gathered in previous experiments. 17. Exposure Time - ANSWER Exposure = Detection + Reaction 18. Visibility vs Detection - ANSWER Visibility is raw telemetry, and detection is capability to alert on that raw telemetry. 19. Zero Trust 3 Concept - ANSWER Ensure all resources are accessed securely regardless of location Adopt a least privileged strategy and strategy enforce access control Inspect and log all traffic 20. SABSA Framework Lifecycle - ANSWER Strategy and Planning Design Implement Manage & Measure 21. QUIC - ANSWER Quick UDP Internet Connections which can be used to bypass scanning of items by operating over UDP port 443 22. Tool: Warberry - ANSWER Collection of scanning tools that run on a raspberry PI 23. Tool: USBDeview - ANSWER View the information on a USB stick such as serial number and more

Show more Read less
Institution
SANS SEC530
Course
SANS SEC530

Content preview

SANS SEC530 EXAM STUDY GUIDE
2026/2027 COMPLETE QUESTIONS WITH
VERIFIED CORRECT ANSWERS ||
100% GUARANTEED PASS
<NEWEST VERSION>


1. Which of the following is a recommended USB keyboard mitigation for sites
requiring high security?


A) Disable USB ports in the system.
B) Restrict USB devices with approved PIDs and VIDs.
C) Block the USB devices physically.
D) Restrict USB devices with approved user accounts. - ANSWER ✔ C)
Block the USB devices physically.


2. Which of the following Cisco IOS commands is used to shut the port down
automatically when the maximum number of MAC addresses is exceeded?


A) switchport port-security violation shutdown
B) switchport port-security limit rate source-mac-shutdown
C) switchport port-security violation auto-shutdown
D) switchport port-security mac-exceed-port-shutdown - ANSWER ✔ A)
switchport port-security violation shutdown

,3. What does DAI stand for, and what does it do? - ANSWER ✔ Dynamic ARP
Inspection (DAI) prevents ARP spoofing at the switch level, by checking a
database of bindings before forwarding an ARP response.


4. How does DHCP starvation work? - ANSWER ✔ A malicious system
attempts to request all available DHCP addresses in the pool.


5. What is the best way to mitigate DHCP starvation attacks? - ANSWER ✔
Most DHCP servers do not have a built-in defense for this type of attack. A
*switch* must be configured to stop this type of attack.


6. What type of attack tends to follow a DHCP starvation attack? - ANSWER
✔ A rouge DHCP server attack.


7. What is the name of the Windows 10 P2P software update setting? -
ANSWER ✔ Delivery Optimization


8. What is the more secure alternative to Windows 10 delivery optimization? -
ANSWER ✔ *WSUS*
Windows Server Update Services


9. What are the *three* types of VLAN ports? - ANSWER ✔ 1) Promiscuous
2) Isolated
3) Community


10.T/F:

, A system on the primary VLAN can also be part of a secondary VLAN, such
as isolated or community VLANS. - ANSWER ✔ True.


11.What type of information is available via NetFlow version 9 logs? -
ANSWER ✔ 1) Byte and packet count
2) Protocol
3) Source and destination IP address
4) IP and TCP flags
5) TCP and UDP ports
6) ICMP types and codes
7) Interface
8) BGP information
and more...


12.SOC Zones - ANSWER ✔ Easy containment of the various needs
throughout the business such as OT/ICS, Manufacturing, R&D, PCI Zones,
business critical applications, cloud critical hosting, and DMZ


13.Time Based Security - ANSWER ✔ How long protection works, and how
long it takes to detect and react. P > D + R


14.Cyber Killchain Countermeasures - ANSWER ✔ Detect, Deny, Disrupt,
Degrade, Decieve


15.Breakout Point - ANSWER ✔ The point in which lateral movement first
occurs, signaling the time in which the attack moves to more computers and
becomes exponentially more dangerous.

, 16.OODA Loop - ANSWER ✔ Observe. Orient. Decide. Act. A teaching tool
originating from military training that promotes the use of a constant cycle
of learning; in digital marketing, used to instill the use of hypothesizing,
experimentation, data capture and measurement, and then re-stating a new
revised hypothesis based on information gathered in previous experiments.


17.Exposure Time - ANSWER ✔ Exposure = Detection + Reaction



18.Visibility vs Detection - ANSWER ✔ Visibility is raw telemetry, and
detection is capability to alert on that raw telemetry.


19.Zero Trust 3 Concept - ANSWER ✔ Ensure all resources are accessed
securely regardless of location
Adopt a least privileged strategy and strategy enforce access control
Inspect and log all traffic


20.SABSA Framework Lifecycle - ANSWER ✔ Strategy and Planning >
Design > Implement > Manage & Measure


21.QUIC - ANSWER ✔ Quick UDP Internet Connections which can be used to
bypass scanning of items by operating over UDP port 443


22.Tool: Warberry - ANSWER ✔ Collection of scanning tools that run on a
raspberry PI


23.Tool: USBDeview - ANSWER ✔ View the information on a USB stick such
as serial number and more

Written for

Institution
SANS SEC530
Course
SANS SEC530

Document information

Uploaded on
April 21, 2026
Number of pages
106
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$15.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ProfBenjamin Havard School
Follow You need to be logged in order to follow users or courses
Sold
642
Member since
1 year
Number of followers
17
Documents
3847
Last sold
2 hours ago
EXCELLENT ACHIEVERS LIBRARY

As a professional tutor, I provide exceptional assistance with homework, quizzes, and exams across various subjects, including Psychology, Nursing, Biological Sciences, Business, Engineering, Human Resource Management, and Mathematics. I am dedicated to offering high-quality support and ensuring that all work meets scholarly standards. To enhance the effectiveness of our services, I work with a team of experienced tutors to create comprehensive and effective revision materials. Together, we are committed to helping students achieve excellent grades through our collaborative efforts and expertise.

Read more Read less
3.8

135 reviews

5
63
4
18
3
33
2
9
1
12

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions