
GIAC Continuous Monitoring Certification
Domain 3Objective 1
HIDS/HIPS/Endpoint Firewalls GMON Practice Questions (Page 7)
Part of the Endpoint and Host Monitoring domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
Questions 31–35
- 31
A security engineer is configuring HIPS on a set of servers that run a critical application. The application is known to use a specific DLL that is also used by a known malware family. The HIPS has a signature that flags the DLL as malicious. The engineer needs to allow the legitimate application to run while still protecting against the malware. Which action is most appropriate?
Select an answer first - 32
Which scenario best illustrates the benefit of integrating HIDS, HIPS, and endpoint firewall on a single endpoint?
Select an answer first - 33
How do HIDS, HIPS, and endpoint firewalls complement each other in a layered endpoint security strategy?
Select an answer first - 34
A company is implementing endpoint firewalls on all employee laptops. The security team wants to ensure that employees can use web browsers and email clients, but the team also wants to block traffic to known malicious domains. Which endpoint firewall feature should the team use to achieve this?
Select an answer first - 35
How does application control contribute to host-based intrusion prevention?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.