
GIAC Continuous Monitoring Certification
Domain 2Objective 1
Network Security Monitoring Tools GMON Practice Questions (Page 3)
Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 11–15
- 11
A company must retain logs for compliance but has limited storage. They also need to be able to search logs quickly for incident response. What is the best strategy?
Select an answer first - 12
An organization wants to automatically block traffic from IP addresses that are known to be malicious according to a commercial threat intelligence feed. They have an existing firewall and SIEM. What is the most effective way to implement this?
Select an answer first - 13
A SOC wants to reduce alert fatigue while ensuring critical alerts are escalated. They have a SIEM that can send alerts via email, SMS, and a ticketing system. The team works 24/7 but has limited staff. What is the best alerting strategy?
Select an answer first - 14
An analyst notices unusual traffic patterns in the network: periodic small outbound connections to a known command-and-control (C2) domain. The team wants to confirm the beaconing behavior and identify which internal hosts are involved. Which combination of tools would be most effective?
Select an answer first - 15
What is the primary difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.