
GIAC Continuous Monitoring Certification
Domain 6Objective 1
Attack Techniques GMON Practice Questions (Page 8)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 36–40
- 36
A threat intelligence analyst is documenting a new adversary group. The group uses spear-phishing emails with malicious LNK files, then employs PowerShell for reconnaissance, and finally exfiltrates data via DNS tunneling. The analyst needs to categorize this behavior for sharing with other organizations. Which representation best characterizes the group's behavior?
Select an answer first - 37
Which of the following is a typical indicator of compromise (IOC) that can be derived from malware behavior analysis?
Select an answer first - 38
Which stage of the attack lifecycle is primarily focused on the attacker identifying vulnerabilities and potential entry points into the target environment?
Select an answer first - 39
During malware analysis, an analyst observes that a sample modifies the hosts file to redirect a known security vendor's domain to 127.0.0.1 and then disables the Windows Defender service. What is the malware's likely objective?
Select an answer first - 40
Which detection strategy is most effective for identifying an attacker using a previously unknown (zero-day) exploit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.