
GIAC Continuous Monitoring Certification
Domain 1Objective 2
Security Architecture Overview GMON Practice Questions (Page 5)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 21–25
- 21
A security architect is designing a multi-layered defense for a critical application. The architect has already deployed a firewall and an IDS. To apply defense in depth, which additional control should be added to protect the application layer?
Select an answer first - 22
A company is deploying a new web application. The security team wants to ensure that monitoring covers the application layer. Which monitoring source is most appropriate for detecting application-layer attacks such as SQL injection?
Select an answer first - 23
Which security architecture component is primarily responsible for inspecting network traffic and generating alerts when suspicious patterns are detected?
Select an answer first - 24
A company is designing a network for a new branch office. They want to protect the internal network from the internet while also providing a place for external partners to access a file server. Which zoning strategy should they use?
Select an answer first - 25
A security architect wants to isolate the payment processing systems from the general corporate network to limit the spread of a potential breach. Which design pattern is most directly applicable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.