Question 1
What is Timesketch used for in FOR508 practice?
Correct Answer:
Scanning for open ports
Explanation:
Timesketch is used to visualize and analyze timelines. It lets you bring together logs and artifacts from multiple sources and place every event on a common time axis, making it easy to see when things happened, how they relate, and how the incident unfolded. You can filter and group events by indicators like IP addresses, user IDs, or event types, which helps reveal the attacker’s sequence of actions, identify correlations, and support reconstructing the incident step by step. It isn’t a ticketing system for managing cases, nor a tool for encrypting logs, and it isn’t a port-scanning utility—those functions belong to separate categories of software. In FOR508 practice, the strength of Timesketch lies in turning scattered data into an coherent timeline that guides investigation and response.
Question 2
Memory-based forensics focuses on which data sources?
Correct Answer:
Live processes, network connections, loaded modules, and memory-resident credentials
Explanation:
Memory-based forensics examines the volatile data held in RAM at the moment of capture. This means looking at what is actively in use by the system and running processes: the live processes and their threads, the open network connections and sockets, the modules loaded into memory (such as DLLs and kernel drivers), and credentials or other sensitive data that reside in memory during operation. This data is transient and can disappear if the system reboots, which is why capturing a memory image is crucial for understanding the exact state of the system at that moment and for uncovering artifacts that may not exist on disk. Disk-based data sources, like disk file system metadata or imaging the entire disk, reflect non-volatile storage and file system structures rather than the current execution state of the machine. Printed documents from the case file are outside digital memory forensics and do not represent volatile artifact data.
Question 3
Which Windows artifact records changes to files and directories on NTFS volumes to aid timeline analysis?
Correct Answer:
USN Change Journal
Explanation:
The main idea here is that the USN Change Journal on NTFS is a built-in audit log that records every change to files and directories on a volume, creating a chronological record that can be used to reconstruct what happened when. Each entry captures what changed (create, delete, modify, rename, attribute change, etc.), when it happened, and which file or directory was affected, including enough details to map actions across the timeline. Because this journal preserves a sequence of events directly from the file system, it provides a reliable backbone for timeline analysis, even if file timestamps are manipulated or multiple artifacts point to the same event. Prefetch files track program startup behavior, not file-system changes themselves. LSASS memory holds sensitive credentials, not a history of file activity. Bash history is Linux shell activity, not Windows NTFS SAMPLEchanges.
Question 4
How do you validate that a memory capture is forensically sound and not tampered with before analysis?
Correct Answer:
Verify the memory dump hash, confirm the capture method used by a trusted tool, and document the chain-of-custody of the memory image
Explanation:
Ensuring a memory capture is forensically sound hinges on three pillars: data integrity, trusted capture methods, and clear chain-of-custody. First, verifying the memory dump hash immediately after capture establishes that the exact bytes collected haven’t been altered since the moment of acquisition. By computing a cryptographic hash (for example, SHA-256) and securely storing that value with the image, you can later confirm the image remains unchanged during handling and analysis. Second, using a capture method known to be trusted by the forensic community helps ensure the tool itself doesn’t modify memory or introduce artifacts. This means selecting a reputable memory acquisition tool and following best practices that minimize disturbance to the system, such as documenting tool version, exact options used, and avoiding unnecessary writes to the source. The goal is reproducibility and verifiability of the capture process. Third, documenting chain-of-custody is essential. Every transfer, storage location, access control, and handling event should be recorded so the evidence can be traced from collection to analysis. This includes who performed the capture, when, where the image is stored, and how access is restricted, providing a verifiable history that supports admissibility and integrity. Why the other ideas don’t fit: a virus scan on the memory image doesn’t prove the image’s integrity or authenticity and could be unreliable; comparing memory to a baseline from another system isn’t a valid validity check due to hardware and configuration differences; rebooting and recapturing changes volatile data and can’t prove that a prior capture was tampered with, since the memory contents aren’t preserved between reboots.
Question 5
The combination of which two ASEP start values can each independently provide persistence for malicious code?
Correct Answer:
0x02 and 0x00
Explanation:
In ASEP, each start value corresponds to a distinct persistence path. The requirement is that each start value, on its own, can maintain persistence for malicious code. The pair 0x00 and 0x02 fits this because each value maps to a separate, standalone persistence mechanism. This means an attacker could rely on either value independently to achieve persistence, and together they present two independent persistence vectors. The other options pair values where at least one does not provide a standalone persistence path, or the persistence outcome depends on combining values, so they don’t meet the criterion of two independent persistence vectors. To defend, monitor and control changes to ASEP start values and block unauthorized persistence mechanisms at startup points.
Question 1
Exam overview

About this Exam

Prepare with the SANS Advanced Incident Response, Threat Hunting, and Digital Forensics (FOR508) Practice test practice quiz. This question bank includes 10 questions covering windows, analysis, provide, incident, and response. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

SANS Advanced Incident Response, Threat Hunting, and Digital Forensics (FOR508) Practice test

This practice set contains 10 questions from the matching question bank and focuses on windows, analysis, provide, incident, and response. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions