
GIAC Continuous Monitoring Certification
Domain 6Objective 2
Exploit Methodology and Analysis GMON Practice Questions (Page 5)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 21–25
- 21
A security team wants to detect exploitation attempts against a web application before they succeed. Which monitoring approach is most effective for early detection?
Select an answer first - 22
A security team wants to detect the use of a known exploit kit that delivers a specific payload. The team has network traffic captures from a previous infection. Which detection method would be most effective?
Select an answer first - 23
During an incident response, an analyst discovers that an attacker exploited a web application vulnerability and then created a new local user account with administrative privileges on the database server. The analyst wants to determine the full scope of the attack. Which post-exploitation technique should the analyst investigate first?
Select an answer first - 24
A penetration tester is developing an exploit for a web application that uses a Content Security Policy (CSP) to restrict script sources. The tester wants to deliver a payload that bypasses the CSP. Which technique should the tester consider?
Select an answer first - 25
Which activity is a core part of vulnerability analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.