Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Enterprise Incident Responder

Domain 4Objective 2

Linux DFIR Fundamentals GEIR Practice Questions (Page 2)

Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
9concepts

Questions 6–10

  1. 6foundation · easy

    Which Linux command lists all currently running processes along with their process IDs (PIDs)?

    Select an answer first
  2. 7application · easy

    You are analyzing a file that was downloaded by an attacker and need to determine when it was last accessed and when its content was last modified. Which command provides both timestamps in a single output?

    Select an answer first
  3. 8expert · hard

    You are analyzing a file that was modified by an attacker. The file's modification time (mtime) has been changed to match a legitimate file's timestamp, but you suspect the content is different. Which metadata attribute would reveal that the file was altered despite the mtime being spoofed?

    Select an answer first
  4. 9foundation · easy

    Which hashing algorithm is commonly used to verify file integrity and is considered cryptographically stronger than MD5?

    Select an answer first
  5. 10foundation · easy

    What is the primary purpose of creating a cryptographic hash of a forensic image?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.