
GIAC Continuous Monitoring Certification
Domain 1Objective 3
Threat Informed Defense GMON Practice Questions (Page 4)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 16–20
- 16
A SOC receives a new threat intelligence report that describes a technique not currently covered by any detection rule. The SOC wants to implement a detection for this technique. What is the first step in the continuous improvement cycle?
Select an answer first - 17
What is the primary purpose of adversary emulation in security monitoring?
Select an answer first - 18
What is the most direct way threat intelligence influences detection rules?
Select an answer first - 19
Which step is a typical part of the continuous improvement cycle for monitoring?
Select an answer first - 20
A security team has a detection rule that was created based on a threat intelligence report from six months ago. The rule has not generated any alerts, and the team is unsure if it is still relevant. What should the team do as part of the continuous improvement cycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.