SANS SEC530 EXAM COVERAGE
The SANS SEC530 exam evaluates a candidate's advanced
knowledge of defensive security operations and modern
enterprise security engineering. The exam coverage
includes secure network architecture design, threat
detection techniques, and advanced logging and
monitoring using SIEM tools. It also assesses skills in
endpoint detection and response (EDR), intrusion
detection systems (IDS/IPS), and traffic analysis for
,identifying malicious activity. Additional areas include
incident response procedures, threat hunting
methodologies, malware analysis fundamentals, and attack
surface reduction strategies. The exam further covers
identity and access management, cloud security
considerations, and application-layer security controls.
Overall, the exam ensures candidates demonstrate the
ability to design, implement, and manage effective
security operations to detect, respond to, and mitigate
advanced cyber threats.
,Which of the following Cisco IOS commands is used to
shut the port down automatically when the maximum
number of MAC addresses is exceeded?
A) switchport port-security violation shutdown
B) switchport port-security limit rate source-mac-
shutdown
C) switchport port-security violation auto-shutdown
D) switchport port-security mac-exceed-port-shutdown
A) switchport port-security violation shutdown
, Which of the following is a recommended USB keyboard
mitigation for sites requiring high security?
A) Disable USB ports in the system.
B) Restrict USB devices with approved PIDs and VIDs.
C) Block the USB devices physically.
D) Restrict USB devices with approved user accounts.
C) Block the USB devices physically.