Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 1Objective 1

Cyber Defense Principles GMON Practice Questions (Page 2)

Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
1concept

Questions 6–10

  1. 6expert · hard

    A security analyst is investigating a potential data breach. The analyst has access to logs from the firewall, the authentication server, and the file server. The analyst notices that a user account was used to access a sensitive file at the same time the user was on vacation. Which action is most appropriate?

    Select an answer first
  2. 7application · medium

    A financial institution is implementing a new monitoring system. The risk team has identified that the highest-impact risk is a compromised administrator account that could be used to transfer funds. The security team must choose a control to mitigate this risk. Which control most directly reduces the likelihood of this specific risk?

    Select an answer first
  3. 8application · medium

    A security engineer is designing a network for a new office. The engineer wants to ensure that if an attacker compromises a workstation, they cannot easily access the finance department's systems. Which design best applies the principle of defense-in-depth?

    Select an answer first
  4. 9expert · hard

    A security architect is designing a monitoring solution for a healthcare organization that must comply with data privacy regulations. The organization wants to detect unauthorized access to patient records while minimizing the risk of exposing sensitive data in logs. Which approach best balances these requirements?

    Select an answer first
  5. 10expert · hard

    A company is implementing a least privilege policy for its development team. Developers need access to production logs to troubleshoot issues, but should not be able to modify production code or configuration. Which approach best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.