
GIAC Continuous Monitoring Certification
Domain 2Objective 2
NIDS/NIPS/NGFW GMON Practice Questions (Page 7)
Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 31–35
- 31
Which factor is most likely to cause an increase in false positives in a signature-based NIDS?
Select an answer first - 32
A SOC analyst sees repeated NGFW alerts for 'SQL injection attempt' from a single internal IP to a web server. The web server logs show no successful SQL injection. The analyst suspects a false positive. Which evidence would best confirm a false positive?
Select an answer first - 33
A security analyst reviews an NIDS alert that shows a high-severity signature match but the associated traffic appears to be a false positive. Which log field is most useful for confirming the false positive?
Select an answer first - 34
An organization wants to enforce security policies based on the identity of the user, not just the IP address. Which NGFW feature enables this capability?
Select an answer first - 35
A large enterprise NIDS is missing attacks because it cannot keep up with peak traffic. The team has already upgraded the hardware. Which tuning strategy is most effective to reduce missed detections without increasing false positives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.