
GIAC Enterprise Incident Responder
Domain 4Objective 2
Linux DFIR Fundamentals GEIR Practice Questions (Page 10)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 46–50
- 46
Which command is used to display active network connections and listening ports on a Linux system?
Select an answer first - 47
You are analyzing a suspicious file in /home/user/.config. You need to determine when the file was last modified, when its metadata was last changed, and when it was last accessed. Which command provides all three timestamps?
Select an answer first - 48
You are responding to a live incident on a Linux system. You need to preserve volatile data before powering off the system. Which of the following should you collect FIRST?
Select an answer first - 49
You are responding to a live Linux server that is part of a critical production environment. The server is actively communicating with a known malicious IP, but taking it offline would cause a major business outage. You need to collect evidence while keeping the system running. Which approach best balances forensic integrity with operational continuity?
Select an answer first - 50
You suspect that a critical system binary, `/usr/bin/sshd`, may have been replaced by an attacker. You have a known-good copy from the original installation media. Which method best verifies whether the binary has been altered?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.