Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 6Objective 1

Attack Techniques GMON Practice Questions (Page 1)

Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts

Questions 1–5

  1. 1expert · hard

    A malware analyst is examining a sample that uses a known Windows API to create a mutex named 'Global\UniqueMutex2024' and then writes a configuration file to the user's AppData folder. The analyst needs to determine if this malware is unique or part of a known family. The analyst has limited time and must choose the most efficient approach. Which approach is most efficient?

    Select an answer first
  2. 2expert · hard

    A SOC analyst is reviewing alerts from a SIEM and sees that a user account has been locked out after multiple failed logon attempts from a single workstation. The analyst also notices that the same workstation has been making connections to an internal file server using a different account. The analyst suspects an attacker is attempting to brute-force credentials and then use them for lateral movement. Which action is most appropriate to confirm the attack technique?

    Select an answer first
  3. 3application · medium

    A security team is reviewing its monitoring strategy after a phishing attack that led to a ransomware deployment. The attack vector was a malicious macro in an Excel spreadsheet. The team wants to improve detection of similar attacks in the future. Which control is most directly aligned with detecting this attack vector?

    Select an answer first
  4. 4application · medium

    A malware analyst is analyzing a sample that, when executed, modifies the Windows registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' to point to a malicious executable. The analyst wants to determine the malware's persistence mechanism and identify a detection opportunity. Which detection is most effective for this persistence mechanism?

    Select an answer first
  5. 5foundation · easy

    When aligning detection strategies with attack techniques, which approach is best suited for detecting an attacker who is using a known malware family?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.