Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 2Objective 3

Perimeter Protection Devices GMON Practice Questions (Page 1)

Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
6concepts

Questions 1–5

  1. 1foundation · easy

    A security analyst notices repeated firewall alerts for denied inbound connections to port 22 from the same external IP address. What does this pattern most likely indicate?

    Select an answer first
  2. 2expert · hard

    A security analyst is responding to an alert from an intrusion prevention system (IPS) indicating that a critical server is sending outbound traffic to a known command-and-control (C2) server. The analyst has confirmed the alert is accurate. The server is essential to business operations and cannot be taken offline. What is the most appropriate response action?

    Select an answer first
  3. 3application · medium

    A network administrator notices that the intrusion prevention system (IPS) at the internet boundary has been generating a high volume of alerts for the past hour, but the security operations center (SOC) has not yet responded. The administrator checks the IPS dashboard and sees that the device's CPU usage is at 95% and the alert queue is growing. What is the most immediate concern for the SOC's ability to detect and respond to a real incident?

    Select an answer first
  4. 4foundation · easy

    In a typical network architecture, where is a firewall most commonly placed to enforce a security boundary between an internal network and an untrusted external network such as the internet?

    Select an answer first
  5. 5foundation · easy

    A security analyst is reviewing the purpose of various perimeter protection devices. Which device is specifically designed to inspect network traffic in real time and actively block malicious packets that match known attack signatures?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.