Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 1Objective 2

Security Architecture Overview GMON Practice Questions (Page 3)

Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
6concepts

Questions 11–15

  1. 11application · medium

    A security analyst is reviewing the architecture of a web application. The application is protected by a web application firewall (WAF), and the backend database is only accessible from the application servers. The analyst wants to add a component that can detect and alert on anomalous database queries that might indicate SQL injection. Which component should be added?

    Select an answer first
  2. 12expert · hard

    A company has a flat network and wants to implement segmentation to improve security and monitoring. The security team wants to detect lateral movement, but the business requires that some servers be accessible from multiple zones. Which design pattern best balances these needs?

    Select an answer first
  3. 13application · medium

    A security architect is designing a monitoring architecture for a multi-site organization. The requirement is to have a centralized view of all security events while ensuring that each site can continue to operate independently if the central connection fails. Which approach best meets this requirement?

    Select an answer first
  4. 14expert · hard

    A security team is troubleshooting a series of alerts from their SIEM. The SIEM is receiving logs from a network IDS, a host-based EDR, and a WAF. The team notices that the IDS generates many false positives, the EDR misses some attacks because it is not fully deployed, and the WAF is only protecting one application. Which action would most effectively improve the overall detection capability?

    Select an answer first
  5. 15application · medium

    A security team is reviewing its monitoring architecture. They have a SIEM that collects logs from firewalls, IDS, and endpoint protection. The team wants to detect an attacker who has moved laterally within the internal network. Which additional data source would most directly improve detection of lateral movement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.