
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 1)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 1–5
- 1
You are analyzing a container image that has multiple layers. You need to determine which layer introduced a specific binary. The image is stored locally on the Docker host. Which method lets you inspect the contents of each layer without running the container?
Select an answer first - 2
How does Kubernetes' automatic container rescheduling affect forensic data collection?
Select an answer first - 3
Which of the following is a common indicator of a container escape attempt?
Select an answer first - 4
Which command or API provides a stream of lifecycle events (e.g., container start, stop, destroy) from the Docker daemon?
Select an answer first - 5
You are investigating a security incident in a Kubernetes cluster. You need to determine when a specific container was started and whether it was restarted after a crash. Which source would provide the most reliable timeline of container lifecycle events for this analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.