
GIAC Continuous Monitoring Certification
Domain 1Objective 1
Cyber Defense Principles GMON Practice Questions (Page 6)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
1concept
Questions 26–30
- 26
A security engineer is configuring a new server that will host a public-facing application. The engineer wants to ensure that if the application is compromised, the attacker cannot easily access other systems on the network. Which configuration best supports this goal?
Select an answer first - 27
A small company hosts a web application on a single server that also contains the database. The server is directly exposed to the internet on ports 80 and 443. The security team wants to implement defense-in-depth without adding significant hardware cost. Which combination of controls provides the most layered protection?
Select an answer first - 28
A company's risk management team is evaluating the risk of a ransomware attack. They determine that the cost of implementing a robust backup and recovery solution is lower than the potential financial loss from an attack. According to risk management principles, what should the company do?
Select an answer first - 29
A security team is implementing a new monitoring system. The team has a limited budget and must choose between two controls: a network-based intrusion detection system (IDS) that covers the entire network, or a host-based security agent that provides deep visibility into each server. The organization's primary concern is a targeted attack that could compromise a single critical server. Which control should the team prioritize?
Select an answer first - 30
A security team is designing a monitoring solution for a multi-site organization. The team wants to ensure that a compromise at one site does not go unnoticed by the central security operations center (SOC). Which approach best supports this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.