
GIAC Enterprise Incident Responder
Domain 4Objective 2
Linux DFIR Fundamentals GEIR Practice Questions (Page 1)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 1–5
- 1
A Linux server is suspected of running a cryptocurrency miner. You need to identify the process, its executable path, and any outbound network connections it has established. Which set of commands provides this information?
Select an answer first - 2
You find a malicious script that persists across reboots. It is not in any cron directory, not in systemd, and not in `/etc/rc.local`. You suspect it is launched through a user's login shell. Which file should you examine to confirm this persistence mechanism?
Select an answer first - 3
You find a suspicious entry in a user's crontab that executes a script every minute. You need to determine when this cron job was added and which user added it. Which files would provide this information?
Select an answer first - 4
An investigator wants to review temporary files that may have been left by an attacker on a Linux system. Which directory is the standard location for temporary files?
Select an answer first - 5
Which directory contains systemd service unit files that define services to start at boot?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.