Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 2Objective 3

Container DFIR Fundamentals GEIR Practice Questions (Page 10)

Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 46–47

  1. 46expert · hard

    You are analyzing a container image that was pulled from a public registry. You suspect that a malicious file was added in a later layer, overwriting a legitimate file from an earlier layer. Which approach would best confirm this and identify the malicious layer?

    Select an answer first
  2. 47application · medium

    You need to acquire a container image from a private registry for offline forensic analysis. The registry requires authentication, and you have valid credentials. Which approach would be most appropriate for acquiring the image while preserving its integrity?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GEIR

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.