
GIAC Continuous Monitoring Certification
Domain 5Objective 1
Account & Privilege Monitoring & Authentication GMON Practice Questions (Page 4)
Part of the Identity and Access Monitoring domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–6 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 16–20
- 16
A security analyst is reviewing logs from a privileged access management (PAM) system. They notice that a user with a standard account has been granted temporary admin rights multiple times in the past week. The user's job role does not require admin access. What should the analyst do?
Select an answer first - 17
Which account lifecycle event should be monitored to detect the creation of unauthorized backdoor accounts?
Select an answer first - 18
Which account type typically requires the most stringent monitoring because it has the potential to change security configurations and access controls?
Select an answer first - 19
An organization wants to detect credential-stuffing attacks against their web application. They have web server logs that include usernames and passwords (hashed). Which pattern in the logs would most likely indicate a credential-stuffing attack?
Select an answer first - 20
A company wants to centralize monitoring of privileged access across on-premises Active Directory and cloud-based IAM. Which approach would provide the most unified view?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.