
GIAC Continuous Monitoring Certification
Domain 6Objective 1
Attack Techniques GMON Practice Questions (Page 3)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 11–15
- 11
Which component of TTPs provides the most specific and detailed description of how an attacker executes a technique, often including exact commands or code snippets?
Select an answer first - 12
What is the primary purpose of analyzing an exploit in the context of continuous monitoring?
Select an answer first - 13
During malware analysis, an analyst discovers that a sample creates a Windows service named 'WindowsUpdateSvc' that runs a binary from a temp directory, and the service is configured to restart automatically if it fails. What does this behavior indicate about the malware's capabilities?
Select an answer first - 14
A threat hunting team is reviewing a report that describes an adversary's TTPs. The report states that the adversary uses living-off-the-land binaries (LOLBins) to perform discovery and lateral movement. How should the team use this information to enhance their hunting activities?
Select an answer first - 15
In the attack lifecycle, which stage typically follows initial compromise and involves the attacker establishing a foothold to maintain access to the compromised system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.