
GIAC Continuous Monitoring Certification
Domain 6Objective 1
Attack Techniques GMON Practice Questions (Page 6)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 26–30
- 26
An incident response team is analyzing a breach where the attacker used a previously unknown vulnerability to gain access, then used a legitimate remote administration tool to move laterally, and finally exfiltrated data via encrypted HTTPS traffic. The team must decide where to focus their detection efforts to prevent future similar attacks. Which detection strategy would be most effective?
Select an answer first - 27
A security analyst is analyzing a memory dump from a compromised server. The analyst suspects that the attacker used a reflective DLL injection to load a payload directly into memory without writing to disk. The analyst needs to confirm this and identify indicators for monitoring. Which approach is most effective?
Select an answer first - 28
A security team is reviewing a recent intrusion where the attacker used a previously unknown exploit for a zero-day vulnerability in a public-facing application. The exploit allowed remote code execution, and the attacker then used living-off-the-land binaries (LOLBins) to move laterally. The team must decide where to focus monitoring to detect similar attacks in the future, given that signature-based detection is ineffective for zero-days. Which strategy is most effective?
Select an answer first - 29
A security analyst is analyzing an exploit that targets a vulnerability in a widely used application. The exploit is known to be used by a specific threat actor. The analyst needs to determine the best way to detect this exploit in the environment. Which approach would provide the most reliable detection?
Select an answer first - 30
A security analyst is reviewing alerts from an endpoint detection and response (EDR) tool. The alert shows that a process spawned from a Microsoft Word document executed a PowerShell command that downloaded a payload from a URL and then ran it. Which attack technique is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.