
GIAC Continuous Monitoring Certification
Domain 1Objective 3
Threat Informed Defense GMON Practice Questions (Page 7)
Part of the Security Monitoring Foundations domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 31–35
- 31
Which activity is a key part of refining detection analytics using threat information?
Select an answer first - 32
What is the primary goal of a threat informed defense strategy in security monitoring?
Select an answer first - 33
A security team regularly reviews detection rules and removes those that have not generated alerts in the past six months. A new threat intelligence report indicates an increase in a specific attack technique that the team had previously deprioritized. What should the team do?
Select an answer first - 34
A security analyst is reviewing threat intelligence that includes a list of malicious IP addresses and domains. The analyst wants to use this intelligence to improve detection. Which approach is most effective?
Select an answer first - 35
A SOC has a detection rule that has been in place for six months. The rule has a low false positive rate, but the SOC is concerned that it may not detect newer variations of the threat. The threat intelligence team has provided updated information on the threat actor's evolving techniques. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMON” is a trademark of its owner, used for identification only.