
GIAC Continuous Monitoring Certification
Domain 5Objective 1
Account & Privilege Monitoring & Authentication GMON Practice Questions (Page 6)
Part of the Identity and Access Monitoring domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–6 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 26–30
- 26
A company uses a SIEM to monitor authentication events. The security team wants to detect a 'golden ticket' attack, where an attacker forges a Kerberos ticket to gain access to any resource. Which monitoring approach would be most effective?
Select an answer first - 27
Why is it important to monitor multi-factor authentication (MFA) usage in authentication logs?
Select an answer first - 28
Which method is commonly used to monitor the use of elevated privileges in a Windows environment?
Select an answer first - 29
A company is implementing continuous monitoring for its identity infrastructure. The security team wants to ensure that all account lifecycle events (creation, modification, deletion) are captured and correlated with user activity. Which approach best achieves this goal?
Select an answer first - 30
A security analyst is investigating a potential brute-force attack on a VPN gateway. The logs show thousands of failed authentication attempts from a single IP address, but no successful logins. The analyst wants to determine if any accounts were compromised. What additional data source would be most useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.