
GIAC Continuous Monitoring Certification
Domain 5Objective 1
Account & Privilege Monitoring & Authentication GMON Practice Questions (Page 3)
Part of the Identity and Access Monitoring domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–6 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 11–15
- 11
An organization's identity team is reviewing the account lifecycle process. They notice that when an employee leaves, their account is disabled but not deleted. The security team wants to ensure that these disabled accounts are not a risk. What is the most important monitoring control to implement?
Select an answer first - 12
A company uses multiple identity providers (IdPs) for different applications. The security team wants to centralize monitoring of authentication and privilege usage across all IdPs. Which approach is most effective?
Select an answer first - 13
What pattern in authentication logs is most indicative of a brute-force attack?
Select an answer first - 14
An auditor requires that all user accounts be reviewed quarterly for necessity. The security team wants to automate the identification of accounts that have not been used in 60 days. What is the most effective way to do this?
Select an answer first - 15
A company uses an IAM system that provisions and deprovisions accounts. The security team wants to detect when a user is provisioned with privileged access that was not approved. Which integration would best support this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.