
GIAC Enterprise Incident Responder
Domain 4Objective 1
Linux Essentials GEIR Practice Questions (Page 6)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
10concepts
Questions 26–29
- 26
An incident responder is analyzing a system that uses systemd. The responder needs to find all log entries related to the SSH service from the last hour, including kernel messages that mention SSH. Which command should be used?
Select an answer first - 27
A network analyst is troubleshooting a server that cannot reach the internet. The server has a static IP address, and the analyst needs to verify the default gateway and DNS configuration. Which commands should be used?
Select an answer first - 28
During a forensic examination of a compromised Linux system, an investigator needs to locate system-wide configuration files that are typically edited by administrators. Which directory in the Linux Filesystem Hierarchy Standard (FHS) is the primary location for such configuration files?
Select an answer first - 29
On a Debian-based Linux distribution, an administrator needs to update the package index from configured repositories before installing a new package. Which command performs this update?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GEIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.