
GIAC Continuous Monitoring Certification
Domain 7Objective 1
Network Data Encryption GMON Practice Questions (Page 8)
Part of the Data Protection domain, which makes up ~7% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
9concepts
Questions 36–40
- 36
A network administrator is configuring a web server to support TLS 1.2 and TLS 1.3. The server currently uses a certificate with an RSA 2048-bit key. Which cipher suite should be prioritized for TLS 1.3 connections?
Select an answer first - 37
Which regulation specifically requires the protection of cardholder data during transmission over open, public networks?
Select an answer first - 38
What is the primary weakness of the DES (Data Encryption Standard) algorithm that led to its deprecation?
Select an answer first - 39
A security analyst is troubleshooting a TLS 1.3 connection that fails to establish. The client and server both support TLS 1.3, but the handshake fails with a certificate error. The server certificate is signed by a private CA that is not installed on the client. Which action should the analyst take to resolve the issue?
Select an answer first - 40
A security team is implementing a key management policy for a hybrid cloud environment. They use a cloud KMS for keys used in the cloud and an on-premises HSM for on-premises keys. A compliance requirement mandates that keys be rotated every 30 days. What is the best practice to ensure compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.