
GIAC Continuous Monitoring Certification
Domain 4Objective 2
Discovery and Vulnerability Scanning GMON Practice Questions (Page 3)
Part of the Configuration and Vulnerability Management domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 11–15
- 11
A security team needs to identify all hosts on a network that are running a specific version of a vulnerable web server. The team has authorization to scan the network. Which scanning technique is most efficient for this task?
Select an answer first - 12
A security analyst needs to discover all active hosts on a network segment that contains both Windows and Linux systems. The analyst has been authorized to scan the segment. Which technique is most effective for host discovery across both operating systems?
Select an answer first - 13
Which factor should most directly influence the frequency of vulnerability scanning in an organization?
Select an answer first - 14
What is the main purpose of vulnerability scanning?
Select an answer first - 15
A security team is evaluating a new vulnerability scanner. The scanner uses only version-based detection and does not perform any authentication. The team wants to reduce false positives. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.