
GIAC Continuous Monitoring Certification
Domain 1Objective 3
Threat Informed Defense GMON Practice Questions (Page 3)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 11–15
- 11
In the context of security monitoring, what does 'threat informed' specifically mean?
Select an answer first - 12
A detection engineer is reviewing a rule that was created based on a threat intelligence report. The rule has a high false positive rate because the technique is also used by legitimate software. The engineer wants to maintain detection while reducing noise. Which approach is most aligned with threat-informed detection engineering?
Select an answer first - 13
A SOC has limited resources and cannot run a full red team exercise. They want to validate their detection coverage for a specific threat actor. They have a test environment and access to an adversary emulation tool. Which approach best balances thoroughness and resource constraints?
Select an answer first - 14
How does threat intelligence primarily inform monitoring strategies?
Select an answer first - 15
A security architect is designing a monitoring strategy for a financial institution. The institution is a likely target for financially motivated threat actors. How should the architect apply threat-informed defense?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.