
GIAC Enterprise Incident Responder
Domain 4Objective 1
Linux Essentials GEIR Practice Questions (Page 2)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
10concepts
Questions 6–10
- 6
A forensic analyst needs to find recently modified files in the /var/log directory and also check the current kernel messages for hardware errors. Which pair of commands should the analyst use?
Select an answer first - 7
On a systemd-based Linux system, an investigator needs to search the system journal for all messages related to the SSH service. Which journalctl command accomplishes this?
Select an answer first - 8
A forensic analyst is examining a compromised CentOS server. The analyst needs to determine if any installed RPM packages have had their files altered. Which command would provide a list of files that have been modified from the package's original state?
Select an answer first - 9
During an incident response, an analyst needs to check the system's uptime, kernel version, and boot parameters to determine if the system was recently rebooted. Which file or directory would provide the kernel boot command line?
Select an answer first - 10
During an incident, a Linux server's `/var/log/syslog` shows repeated OOM-killer messages. The analyst suspects a specific process is consuming excessive memory. Which command would immediately show the current memory usage of all processes sorted by resident memory size?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.