SANS SEC 301 ACTUAL EXAM Review NEWEST 2025-2026
COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS
(VERIFIED ANSWERS) |ALREADY GRADED A+||BRAND NEW
VERSION!!
Terms in this set (108)
What type of systems do you Public Access Systems
put in the DMZ?
A. A DMZ has no servers, just
client PCs
B. Servers with sensitive data
only
C. Firewalls
D. Public
Access Systems
When is it justified to put Never
public access servers on an
internal network?
A. Never
B. As long as they are fully
patched
C. When that is the most
convenient way to access
them
D. We always do that
/ 1/34
,9/22/25, 10:37 PM SEC301 Review Questions
What is the acronym for IDS
an automated system that
watches for signs of an
attack called?
A. DNS
B. IPS
C. ISP
D. IDS
When an IDS watches for Signature Analysis
patterns of an attack in
packets, what is it doing?
A. Signature Analysis
B. Intrusion Detection and
Prevention (IDP)
C. You can't do that
D. Anomaly analysis
To stop attacks, an Intrusion IDS
Protection System must
also be what?
A. DNS
B. IPS
C. ISP
D. IDS
When there is no valid A Honeypot
reason for anyone to access
an IT resource, what do you
call that resource?
A. A Honeypot
B. A Sweetpot
C. Why would you do that?
D. A nonresource
/ 2/34
,9/22/25, 10:37 PM SEC301 Review Questions
What is a common name for Content Filter
a solution that prevents
inappropriate web
surfing?
A. Unnecessary
B. Content Filter
C. WebSense
D. Surfing Ruleset
What is another name for an Unified Threat Management (UTM)
all-in-one security
appliance?
A. A Honeypot
B. This is nothing but a
marketing term - they
don't really exist
C. Layered Management
Application Firewall
D. Unified Threat Management
(UTM)
What is the less common but Protocol Analyzer
more accurate name for a
sniffer?
A. Protocol Dissector
B. Wireshark
C. Protocol Analyzer
D. Packet Capture
/ 3/34
, 9/22/25, 10:37 PM SEC301 Review Questions
What are two prerequisites You have to know the IP Address
for attacking a system
remotely? (choose two) You have to know the port number you will connect to
A. You have to know the IP
Address
B. You have to know the
operating system and
version
C. You have to know the
server software and
version
D. You have to know the
port number you will
connect to
What is the name of the Nmap Zenmap
GUI?
A. Nmap
B. WinMap
C. Zenmap
D. NmapFE
What is a common They both give a lot of false positives
problem of both network
and host vulnerability
scanners?
A. Neither can do port
scanning
B. They both give a lot of false
positives
C. They both give a lot of false
negatives
D. Neither can determine patch
level
/ 4/34