Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 2Objective 3

Perimeter Protection Devices GMON Practice Questions (Page 2)

Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    A firewall alert indicates that a workstation on the internal network is communicating with a known malicious command-and-control server. What is the FIRST step in the response process?

    Select an answer first
  2. 7expert · hard

    A security analyst is responding to an alert from a firewall indicating that a user's workstation is communicating with a known malicious IP address. The analyst has confirmed the alert is accurate. The workstation is used by a senior executive who is currently in an important meeting and cannot be disturbed. What is the most appropriate response action?

    Select an answer first
  3. 8application · medium

    A company is implementing a policy that only allows company-issued laptops to connect to the corporate network. They want to ensure that any unauthorized device that tries to connect is blocked and logged. Which perimeter protection device is BEST suited for this task?

    Select an answer first
  4. 9expert · hard

    A firewall administrator is configuring rules on a firewall that handles traffic for a large organization. The organization has a policy that requires all traffic to be logged, but the firewall's logging capability is limited and cannot handle the volume of logs generated by all traffic. The administrator needs to ensure that all traffic is logged while minimizing the impact on the firewall's performance. Which approach is most effective?

    Select an answer first
  5. 10expert · hard

    A network operations team is monitoring the health of a firewall that is critical to the organization's security. They have noticed that the firewall's memory utilization has been steadily increasing over the past few weeks, and they are concerned about a potential outage. They have also noticed that the firewall's log files are growing rapidly. What is the most likely cause of the memory increase, and what should the team do to address it?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.