
GIAC Enterprise Incident Responder
Domain 2Objective 3
Container DFIR Fundamentals GEIR Practice Questions (Page 7)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 31–35
- 31
How does OverlayFS combine the read-only layers of a container image with the writable layer?
Select an answer first - 32
A security analyst needs to determine which host processes belong to a specific container that is suspected of network reconnaissance. The container was started with Docker using the default network mode. Which combination of commands provides the most direct mapping of container processes to host processes and associated network connections?
Select an answer first - 33
A container on a Linux host is suspected of performing network scanning. The container was started with the default Docker network mode. Which host-level command would let you capture the container's outbound network traffic and associate it with the container's network namespace?
Select an answer first - 34
Which tool can be used to capture network traffic associated with a specific container's network namespace?
Select an answer first - 35
What is the primary role of a container orchestrator like Kubernetes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.