
GIAC Continuous Monitoring Certification
Domain 3Objective 1
HIDS/HIPS/Endpoint Firewalls GMON Practice Questions (Page 8)
Part of the Endpoint and Host Monitoring domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 4–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
10concepts
Questions 36–37
- 36
A SOC analyst is reviewing HIDS alerts from a Linux server. The HIDS has generated a high volume of alerts for failed SSH login attempts from a single IP address. The analyst wants to reduce the noise while still being alerted to successful brute-force attacks. What is the most appropriate action?
Select an answer first - 37
A security architect is designing endpoint protection for a high-security environment. The environment includes servers that process classified data and must be protected against both known and unknown threats. The architect has budget for only one additional control beyond the existing HIDS deployment. The primary threat model includes zero-day exploits and insider threats. Which control provides the most comprehensive protection against this threat model?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GMON
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.