Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Linux Incident Responder

GLIR

The GIAC Linux Incident Responder (GLIR) certification validates deep command-line and triage acumen in Linux environments, a differentiator for modern DFIR and threat hunting teams. It proves you can conduct system triage, collect evidence, and analyze intrusions to identify the initial entry point and lateral movement across Linux systems. Ideal for incident responders, threat hunters, and SOC analysts who need to defend Linux infrastructure.

508 practice questions · Updated 2026-07-30

4Domains
13Objectives
99Concepts
508Questions

GLIR Curriculum

Every domain, objective, and concept the GLIR exam measures.

Linux OS Fundamentals

18 concepts · 62 questions
  1. Linux Boot Process
  2. Runlevels and Targets
  3. Systemd Essentials
  4. File System Hierarchy Standard (FHS)
  5. File Types and Permissions
  6. Special Permissions and Attributes
  7. Hard Links and Symbolic Links
  8. Mounting and Unmounting File Systems
  9. Disk Usage and Inodes
  10. Process Management
  11. Environment Variables and Shell Configuration
  12. Package Management
  13. Logging and Journaling
  14. System Monitoring and Performance
  15. User and Group Management
  16. Networking Fundamentals
  17. Service and Socket Activation
  18. System Initialization and Configuration Files

Linux OS File System Structure

8 concepts · 43 questions
  1. File System Hierarchy
  2. File Types
  3. Inodes and Metadata
  4. Mount Points and Filesystems
  5. Permissions and Ownership
  6. Hard Links and Symbolic Links
  7. File System Navigation Commands
  8. File System Forensics Basics
  1. Linux File System Hierarchy
  2. File Types and Permissions
  3. Inodes and Metadata
  4. Hard Links and Symbolic Links
  5. Mount Points and File Systems
  6. File System Analysis Tools

Linux File System Artifacts

6 concepts · 35 questions
  1. File System Hierarchy
  2. File Metadata and Timestamps
  3. File System Journaling and Logs
  4. Artifact Locations
  5. File System Mounting and Partitions
  6. Deleted File Recovery

Linux OS Event Log Introduction

1 concepts · 32 questions
  1. Linux OS Event Log Introduction

Analyzing Linux Events

9 concepts · 36 questions
  1. Linux Event Sources
  2. Syslog and journald
  3. Auditd framework
  4. Log file locations and formats
  5. Timestamps and time zones
  6. Event correlation
  7. Timeline analysis techniques
  8. Common Linux event types
  9. Log analysis tools

Analyzing Linux Application Events

8 concepts · 34 questions
  1. Identify Application Event Sources
  2. Parse Application Log Formats
  3. Correlate Application Events with System Activity
  4. Analyze Authentication and Authorization Events
  5. Analyze Application Errors and Anomalies
  6. Trace User Actions Across Applications
  7. Detect Malicious Application Behavior
  8. Utilize Timeline Analysis Tools

Linux Timeline Analysis

8 concepts · 45 questions
  1. Timeline Analysis Fundamentals
  2. Acquiring and Normalizing Timestamps
  3. Building a Super Timeline
  4. Correlating Events Across Artifacts
  5. Filtering and Searching Timelines
  6. Identifying Anomalous Activity
  7. Using Timeline Analysis Tools
  8. Interpreting Timeline Results

Incident Response Triage

6 concepts · 48 questions
  1. Triage Process Overview
  2. Evidence Identification
  3. Evidence Preservation
  4. Initial Assessment
  5. Prioritization Criteria
  6. Triage Documentation

Evidence Collection and Mounting

5 concepts · 28 questions
  1. Evidence Collection Fundamentals
  2. Mounting Filesystems Read-Only
  3. Using Mount Options for Forensic Integrity
  4. Handling Encrypted or Special Filesystems
  5. Documenting Mounting Procedures

Analyzing Anti-Forensics Techniques

7 concepts · 33 questions
  1. Identify anti-forensics techniques
  2. Detect data hiding methods
  3. Detect artifact wiping and destruction
  4. Detect log tampering and manipulation
  5. Detect encryption and obfuscation
  6. Analyze anti-forensics impact on evidence
  7. Apply countermeasures to anti-forensics

  1. Memory Acquisition
  2. Memory Analysis Tools
  3. Process and Network Artifacts
  4. Kernel Memory Structures
  5. Device Profiling Fundamentals
  6. Device Artifact Analysis
  7. Correlating Memory and Device Evidence
  1. Threat Hunting Fundamentals
  2. Linux Artifact Analysis
  3. Process and Memory Forensics
  4. Persistence Mechanisms
  5. Lateral Movement Detection
  6. Threat Hunting with Sysmon and Auditd
  7. YARA Rule Development
  8. Network Traffic Analysis
  9. Incident Response Playbooks
  10. Threat Intelligence Integration
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GLIR, so none is invented.