
GIAC Continuous Monitoring Certification
Domain 4Objective 2
Discovery and Vulnerability Scanning GMON Practice Questions (Page 6)
Part of the Configuration and Vulnerability Management domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 26–30
- 26
A security analyst is asked to scan a partner network that is connected to the company's network via a VPN. The analyst has authorization to scan the company's network but not the partner's network. What should the analyst do?
Select an answer first - 27
A security analyst is setting up a discovery scan for a new office subnet. The analyst has been given the IP range 192.168.10.0/24 and has authorization to scan it. The analyst wants to identify all active hosts and the services they are running. Which approach is most appropriate?
Select an answer first - 28
How does a vulnerability scanner typically identify known vulnerabilities on a system?
Select an answer first - 29
A vulnerability scan reports that a web application is vulnerable to SQL injection. The application team reviews the code and finds that all user inputs are parameterized. How should the security analyst classify this finding?
Select an answer first - 30
Which combination of factors is most important when prioritizing vulnerability remediation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.