
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 2)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 6–10
- 6
What is the forensic value of container runtime logs (e.g., containerd logs)?
Select an answer first - 7
During incident response on a compromised Linux host, you identify a suspicious process with PID 4821 that appears to be running inside a container. You need to confirm which container it belongs to and map it to the container's filesystem and network namespace. Which command sequence would provide the most direct evidence for this mapping?
Select an answer first - 8
You are investigating a Kubernetes cluster where a container was killed by the OOM killer. You need to determine which process in the container was responsible for the memory exhaustion. Which source would provide the most direct evidence?
Select an answer first - 9
Which component is responsible for actually launching and supervising container processes on a Linux host?
Select an answer first - 10
You are investigating a Kubernetes node that uses CRI-O as its container runtime. You need to collect the container's logs and configuration for forensic analysis. Which command or tool would be most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.