Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 6Objective 1

Attack Techniques GMON Practice Questions (Page 5)

Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts

Questions 21–25

  1. 21application · medium

    During an incident review, a security team maps the attacker's actions to the Cyber Kill Chain. They observe that the attacker delivered a weaponized PDF via a spear-phishing email, which then installed a backdoor that beaconed to an external server. Later, the attacker used stolen credentials to access a file server and began staging data. At which stage of the kill chain should the team focus their monitoring to detect the attack earliest?

    Select an answer first
  2. 22foundation · easy

    In the context of threat intelligence, what does the 'T' in TTPs specifically refer to?

    Select an answer first
  3. 23expert · hard

    A security analyst is investigating an alert that shows a user downloaded a file from a file-sharing site, and then the file executed a PowerShell script that made an outbound connection to a non-standard port. The analyst needs to determine if this is a malicious attack or a false positive. Which piece of evidence would most strongly indicate a malicious attack?

    Select an answer first
  4. 24application · medium

    During an incident response, the team reconstructs the attack timeline: an employee clicked a link in a phishing email, which led to a drive-by download of a remote access trojan (RAT). The RAT established a C2 channel and then downloaded additional tools. The attacker used these tools to enumerate the network and eventually exfiltrated data. The team wants to identify the earliest detection point that would have allowed them to stop the attack before data exfiltration. Which stage should they prioritize for monitoring?

    Select an answer first
  5. 25application · medium

    A malware analyst is analyzing a sample that, when executed, injects code into a legitimate process (e.g., svchost.exe) and then communicates with a C2 server using HTTP. The analyst wants to identify a detection opportunity that is specific to this malware's behavior. Which detection is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.