
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 6)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 26–30
- 26
During a forensic analysis of a container image, you need to determine which layer introduced a specific malicious file. You have access to the image's manifest and the host's overlay2 directory. Which approach would most efficiently identify the layer containing the file?
Select an answer first - 27
Which cgroup subsystem would an investigator examine to determine the memory limit assigned to a container?
Select an answer first - 28
During a forensic review of a compromised container, you find that the container was running with `--privileged` and had the `CAP_SYS_ADMIN` capability. The container also had a mount namespace that included the host's `/etc` directory. Which finding is the strongest indicator of a potential container escape?
Select an answer first - 29
What is the primary purpose of control groups (cgroups) in container technology?
Select an answer first - 30
You need to determine whether a container shares the host's network namespace. Which command would you run on the host to check this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.