
GIAC Continuous Monitoring Certification
Domain 2Objective 3
Perimeter Protection Devices GMON Practice Questions (Page 3)
Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
6concepts
Questions 11–15
- 11
A security operations center (SOC) is reviewing logs from a network access control (NAC) system and notices that a device that was previously quarantined for a malware infection is now back on the network and is again exhibiting the same malicious behavior. The SOC also notices that the NAC system's logs show the device was released from quarantine by an administrator. What is the most likely reason the device was released, and what should the SOC do?
Select an answer first - 12
A security team is configuring a firewall to protect a web application. The application is a critical business system, and the team wants to ensure high availability. They are considering two configurations: (1) a single firewall with a rule that allows all traffic from the application's load balancer IP, or (2) a pair of firewalls in an active-passive high-availability cluster with a rule that allows traffic from the load balancer IP and also includes a rule to log all traffic from the load balancer. Which configuration is more resilient and provides better monitoring?
Select an answer first - 13
A large organization is redesigning its network. They have a critical application that must be accessible to employees both from the internal network and from the internet via VPN. The application also needs to be isolated from the general internal network due to compliance requirements. The security team is considering two architectures: (1) placing the application in a DMZ with firewalls on both sides, or (2) placing the application on a separate VLAN with a firewall between the VLAN and the internal network, and a VPN concentrator in the DMZ. Which architecture is MORE secure and why?
Select an answer first - 14
An intrusion prevention system (IPS) has detected and blocked a series of exploit attempts against a public-facing web server. The attacks are coming from multiple different IP addresses, but they all use the same exploit signature. The IPS has blocked the individual attacks, but the attempts are continuing. What is the most effective next step to mitigate this ongoing threat?
Select an answer first - 15
A security team wants to be notified when a perimeter IPS device becomes unresponsive or fails. Which monitoring method is best suited for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.