
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 5)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 21–25
- 21
Which namespace provides a container with its own view of the system's process table, so that the container's PID 1 is not the host's PID 1?
Select an answer first - 22
A container has been deleted from a Docker host, but you need to recover its filesystem for forensic analysis. Which location on the host is most likely to contain remnants of the container's writable layer?
Select an answer first - 23
During an incident, you discover that a container was able to consume far more CPU than its configured cgroup limit. The container was started with Docker using `--cpu-shares` but no `--cpus` or `--cpu-quota`. Which explanation best accounts for this observation?
Select an answer first - 24
Where does Docker typically store container configuration and metadata on a Linux host?
Select an answer first - 25
You are analyzing a host that runs containers using CRI-O as the runtime. You need to find the logs for a specific container that has already been terminated. Which location is most appropriate to look for the container's logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.