Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Continuous Monitoring Certification

Domain 1Objective 3

Threat Informed Defense GMON Practice Questions (Page 5)

Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 21–25

  1. 21application · medium

    A SOC team wants to validate that their detection rules for a specific adversary group are effective. They have a test environment that mirrors production. Which adversary emulation approach is most appropriate?

    Select an answer first
  2. 22application · medium

    A SOC has implemented a new detection rule based on a threat intelligence report. After a month, the team reviews the rule's performance and finds that it has generated many false positives. What is the best next step in the continuous improvement cycle?

    Select an answer first
  3. 23application · medium

    A company's SOC has implemented new detection rules based on a recent threat report. The team wants to validate that the rules actually fire when an attacker uses the described techniques. Which approach best tests the monitoring capabilities in a controlled way?

    Select an answer first
  4. 24application · medium

    A security operations center (SOC) receives a threat intelligence report describing a new campaign that uses PowerShell to download a payload from a specific domain and then executes it via a scheduled task. The SOC wants to create a detection that will alert on this activity. Which approach best applies threat-informed detection engineering?

    Select an answer first
  5. 25expert · hard

    A security architect is designing a monitoring strategy for an organization that faces a diverse set of threats, including opportunistic malware and targeted APT groups. The architect wants to implement threat informed defense. Which approach best balances the need to cover both types of threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.