Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 2Objective 3

Container DFIR Fundamentals GEIR Practice Questions (Page 9)

Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    Which command can be used to export a container's filesystem to a tar archive for forensic analysis?

    Select an answer first
  2. 42application · medium

    You are responding to an incident in a Kubernetes cluster where a pod ran a malicious container that has since been deleted. You need to collect forensic evidence from the node that hosted the pod. Which source is most likely to contain records of the container's creation, execution, and deletion?

    Select an answer first
  3. 43foundation · easy

    What is the first step in acquiring a container image from a registry for forensic analysis?

    Select an answer first
  4. 44foundation · easy

    How can an investigator map a container process to the corresponding host process?

    Select an answer first
  5. 45foundation · easy

    Which container configuration, if present, could indicate a weak isolation boundary and increase the risk of escape?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.