
GIAC Continuous Monitoring Certification
Domain 2Objective 2
NIDS/NIPS/NGFW GMON Practice Questions (Page 5)
Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 21–25
- 21
A security team is evaluating a NIDS that uses behavioral detection. The NIDS has been running for a week and has generated several alerts for unusual outbound traffic patterns. The team wants to determine if these alerts indicate a real compromise or just normal variation in network usage. Which approach is most effective?
Select an answer first - 22
A security analyst is reviewing a NIDS alert that fired on a signature for a known remote code execution exploit. The alert shows a source IP from a partner network and a destination IP of an internal web server. The web server logs show no successful exploitation, but the alert repeats every few minutes. The analyst suspects the signature is matching a benign pattern in the application's traffic. Which action is most appropriate to confirm the suspicion?
Select an answer first - 23
A manufacturing company must inspect all traffic between its OT network and the corporate IT network. The security team needs to block known malicious signatures immediately, but also wants to allow legitimate industrial protocols that are not yet fully documented. Which deployment approach best meets these requirements?
Select an answer first - 24
A security architect is deciding where to place a network security device to monitor traffic between two internal network segments. The device must be able to block malicious traffic in real time, but the network team is concerned about adding latency to a latency-sensitive application. Which deployment mode and device type is most appropriate?
Select an answer first - 25
A NIDS alert shows a high-severity signature match for a known exploit against a web server. The analyst checks the server logs and finds no successful exploitation, but the alert repeats every few minutes. Which initial step is most appropriate to determine if this is a true positive or a false positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.