
GIAC Continuous Monitoring Certification
Domain 2Objective 4
Proxies & SIEM GMON Practice Questions (Page 4)
Part of the Network Monitoring and Protection domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
9concepts
Questions 16–20
- 16
Which protocol is commonly used to forward proxy logs to a SIEM?
Select an answer first - 17
After proxy logs are ingested into a SIEM, what is the next logical step to enable effective monitoring?
Select an answer first - 18
Which of the following is a core function of a Security Information and Event Management (SIEM) system?
Select an answer first - 19
A SIEM administrator is integrating proxy logs from multiple regional offices. Each office uses a different proxy vendor, and the log formats differ significantly. The administrator wants to create a unified correlation rule that works across all offices. Which step is essential before creating the rule?
Select an answer first - 20
Which SIEM feature is used to reduce false positives by grouping related events into a single incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.