
GIAC Continuous Monitoring Certification
Domain 6Objective 2
Exploit Methodology and Analysis GMON Practice Questions (Page 8)
Part of the Attack and Exploit Analysis domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 36–40
- 36
A vulnerability scanner reports a critical vulnerability in a custom application. The scanner provides a CVSS score but no exploit code. The team needs to determine the actual risk to the organization. Which action is most appropriate?
Select an answer first - 37
What is the primary purpose of applying security patches to software?
Select an answer first - 38
A security team is reviewing a series of alerts that show an attacker first performed a port scan, then exploited a vulnerability in a database service, and finally used the compromised database server to access other systems on the network. Which stage of the exploit lifecycle does the final action represent?
Select an answer first - 39
In vulnerability analysis, what is the primary purpose of a Common Vulnerability Scoring System (CVSS) score?
Select an answer first - 40
A security engineer is reviewing a vulnerability scan and finds that a web application is vulnerable to cross-site scripting (XSS). The application is scheduled to be replaced in six months. Which mitigation should the engineer implement to reduce the risk in the interim?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GMON
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.