
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 4)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 16–20
- 16
During an incident, you need to acquire the full filesystem of a compromised container that is still running on a Docker host. The container uses the default overlay2 storage driver. Which approach preserves the most forensic value from the container's writable layer?
Select an answer first - 17
Which container runtime is commonly used by Kubernetes as a lightweight, high-level runtime that manages image transfer and container lifecycle, but delegates process execution to a lower-level runtime?
Select an answer first - 18
You are investigating a container image that was pulled from a private registry. You need to analyze the image's layers to determine if a malicious file was added in a specific layer. Which approach gives you the ability to examine each layer individually?
Select an answer first - 19
In a container image, what is the primary purpose of the writable layer created when a container starts?
Select an answer first - 20
Which Linux namespace is primarily responsible for isolating a container's filesystem view?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.