
GIAC Continuous Monitoring Certification
Domain 1Objective 3
Threat Informed Defense GMON Practice Questions (Page 2)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 6–10
- 6
A security operations center receives a threat intelligence feed that includes a list of malicious IP addresses. The team wants to use this intelligence to improve monitoring. What is the most effective way to integrate this feed?
Select an answer first - 7
A security team has implemented a new detection rule for credential dumping based on a recent threat intelligence report. Before relying on it, the team wants to validate that the rule actually fires when the adversary's technique is used. Which action best tests the detection capability?
Select an answer first - 8
A security team is planning an adversary emulation exercise. They have a limited budget and cannot emulate all techniques. They want to maximize the improvement to their monitoring capabilities. Which approach is most effective?
Select an answer first - 9
A security manager is evaluating the organization's monitoring program. The program currently uses a compliance checklist to determine what to monitor. The manager wants to adopt a threat-informed defense approach. Which change is most critical?
Select an answer first - 10
What is the purpose of the continuous improvement cycle in threat-informed monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.