Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 1Objective 1

Cyber Defense Principles GMON Practice Questions (Page 3)

Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
1concept

Questions 11–15

  1. 11application · medium

    A security engineer is designing access controls for a cloud storage bucket that contains sensitive customer data. The company policy states that only the data analytics team should have read access, and only the data engineering team should have write access. The engineer wants to implement least privilege. Which approach is the most appropriate?

    Select an answer first
  2. 12application · medium

    A security analyst is reviewing the access controls for a database that stores customer payment card data. The database administrator has a single account with full administrative privileges that is used for both routine maintenance and emergency break-glass access. The analyst wants to reduce the risk of credential misuse while still ensuring that the administrator can perform urgent tasks. Which approach best aligns with the principle of least privilege?

    Select an answer first
  3. 13application · medium

    A risk assessment for a hospital's patient portal identifies that a data breach could result in regulatory fines and loss of patient trust. The hospital decides to implement mandatory encryption for all patient data at rest and in transit. This decision is an example of which risk management strategy?

    Select an answer first
  4. 14application · medium

    A company is designing a new customer-facing web application. The security team wants to implement defense-in-depth. Which combination of controls best exemplifies this principle?

    Select an answer first
  5. 15foundation · easy

    Which principle of cyber defense is best described by implementing multiple independent security controls so that if one control fails, another still provides protection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.