
GIAC Enterprise Incident Responder
Domain 4Objective 2
Linux DFIR Fundamentals GEIR Practice Questions (Page 8)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 36–40
- 36
Which command displays the current routing table on a Linux system?
Select an answer first - 37
Which log file records successful and failed login attempts on a typical Debian-based Linux system?
Select an answer first - 38
You are investigating a suspicious binary in /tmp. You need to determine whether the file was modified after it was initially placed on the system and whether it matches a known-good hash from the vendor. Which command sequence provides the most useful forensic data?
Select an answer first - 39
You are performing live response on a compromised Linux system. You need to collect volatile data while minimizing the impact on the system. Which of the following is the most appropriate order of collection?
Select an answer first - 40
During an incident investigation, you discover a suspicious process that is not visible in the normal process list. You suspect it may be hidden using a rootkit. Which of the following actions is most likely to reveal the hidden process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.