
GIAC Linux Incident Responder
Domain 3Objective 3
Analyzing Anti-Forensics Techniques GLIR Practice Questions (Page 2)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 6–10
- 6
During an incident response engagement, an analyst discovers that a Linux system has been configured with a hidden directory that is only accessible via a specific command, and the system logs show no record of the directory's creation. Which anti-forensics technique is being demonstrated?
Select an answer first - 7
You are investigating a Linux system where the attacker cleared the bash history and also modified the /var/log/wtmp file to remove evidence of their login. Which of the following actions would best help you recover evidence of the attacker's activities?
Select an answer first - 8
A Linux server was compromised, and the attacker used a secure erase tool to wipe specific files before you could acquire evidence. During your investigation, you notice that the filesystem journal (e.g., ext4 journal) still contains remnants of the deleted files. Which action would best preserve this potential evidence?
Select an answer first - 9
An attacker is known to have cleared the bash history and modified the `/var/log/wtmp` file to hide their login activity. Which of the following actions would best help you recover evidence of the attacker's commands?
Select an answer first - 10
You are setting up a Linux server that will be used for incident response investigations. To mitigate log tampering by attackers, which configuration would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.