
GIAC Continuous Monitoring Certification
Domain 6Objective 2
Exploit Methodology and Analysis GMON Practice Questions (Page 1)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 1–5
- 1
A security analyst is testing an exploit against a target application. The exploit fails when the application is running with certain security features enabled. Which security feature is most likely preventing the exploit from succeeding?
Select an answer first - 2
What is the primary goal of lateral movement in post-exploitation?
Select an answer first - 3
Which stage of the exploit lifecycle involves the attacker performing actions to maintain access to a compromised system?
Select an answer first - 4
An exploit developer needs to create a payload that evades antivirus detection while still maintaining functionality. The payload must execute a reverse shell and then download additional tools. Which approach is most likely to succeed?
Select an answer first - 5
In the context of the exploit lifecycle, which stage immediately follows the initial discovery of a vulnerability in a target system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.