Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 4Objective 2

Discovery and Vulnerability Scanning GMON Practice Questions (Page 5)

Part of the Configuration and Vulnerability Management domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
8concepts

Questions 21–25

  1. 21application · medium

    A security team runs a vulnerability scan on a new application server and finds several high-severity vulnerabilities. The team wants to confirm which findings are actually exploitable before sending them to the remediation team. What is the most appropriate next step?

    Select an answer first
  2. 22application · medium

    A security team needs to discover all active hosts on a large, segmented network. They have been given authorization to scan all segments, but they want to minimize the time and network impact of the discovery phase. Which technique is most appropriate for this task?

    Select an answer first
  3. 23application · medium

    A vulnerability scan found a critical vulnerability on a server that is listed in the CMDB as 'owner unknown'. The server is used by multiple departments. The security team needs to remediate the vulnerability. What should be the first step?

    Select an answer first
  4. 24application · medium

    A security analyst at a financial firm is asked to improve the discovery scanning program. The firm has a strict change-management policy that requires all active scans to be approved by the change advisory board (CAB) at least 72 hours in advance. The analyst wants to run a full discovery scan of the internal network every Friday night to catch new assets added during the week. Which approach best balances the firm's change-management requirement with the need for timely asset discovery?

    Select an answer first
  5. 25foundation · easy

    What is the primary reason to obtain written authorization before conducting a vulnerability scan?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.