
GIAC Linux Incident Responder
Domain 3Objective 3
Analyzing Anti-Forensics Techniques GLIR Practice Questions (Page 1)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 1–5
- 1
You are the lead incident responder for a company that experienced a breach. The attacker used multiple anti-forensics techniques, including log tampering, file wiping, and encryption. You have a forensic image of the compromised server, but the attacker also wiped the system logs and encrypted some files. You need to present evidence in court. Which factor is most likely to affect the admissibility of the evidence?
Select an answer first - 2
You are the incident responder for a company that experienced a data breach. The attacker used anti-forensics techniques, including log tampering and file wiping. You have collected evidence, but the logs are incomplete. You need to determine the scope of the breach. Which factor is most important for assessing the impact of the anti-forensics techniques on your investigation?
Select an answer first - 3
A forensic examiner discovers a binary file on a Linux system that has been compressed and then encrypted, making it impossible to analyze without the decryption key. Which anti-forensics technique is being used?
Select an answer first - 4
You are examining a Linux system and suspect that an attacker hid data in the slack space of a file. Which tool or method would be most effective for detecting data hidden in slack space?
Select an answer first - 5
On a Linux system, an investigator discovers that a file has been deliberately placed in the slack space of an existing file's allocated cluster. What is the primary purpose of this technique?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.