Hacker Tools Techniques Exploits and Incident Handling

Here you have the best SANS SEC504 practice exam questions

  • You have 328 total questions to study from
  • Each page has 5 questions, making a total of 66 pages
  • You can navigate through the pages using the buttons at the bottom
  • This questions were last updated on December 30, 2025
  • This site is not affiliated with or endorsed by SANS.
Question 1 of 328
Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an enterprise?
Correct Answer: A

Question 2 of 328
Which of the following statements are true about netcat?
Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A, B, C

Question 3 of 328
Which of the following is a reason to implement security logging on a DNS server?
Correct Answer: C

Question 4 of 328
The Klez worm is a mass-mailing worm that exploits a vulnerability to open an executable attachment even in Microsoft Outlook's preview pane. The Klez worm gathers email addresses from the entries of the default Windows Address Book (WAB). Which of the following registry values can be used to identify this worm?
Correct Answer: B

Question 5 of 328
You work as a Network Administrator for Net Perfect Inc. The company has a Windows-based network. The company wants to fix potential vulnerabilities existing on the tested systems. You use Nessus as a vulnerability scanning program to fix the vulnerabilities. Which of the following vulnerabilities can be fixed using
Nessus?
Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A, B, C