
GIAC Linux Incident Responder
Domain 3Objective 3
Analyzing Anti-Forensics Techniques GLIR Practice Questions (Page 5)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 21–25
- 21
You are analyzing a Linux system and find a file that appears to be a JPEG image, but its size is much larger than expected. You suspect steganography. You also notice that the file's extended attributes (xattr) contain unusual data. Which approach would be most effective for detecting hidden data in both the file and its extended attributes?
Select an answer first - 22
During an incident response, an attacker uses a secure erase tool to overwrite a critical log file before the system is shut down. What is the primary impact of this action on the digital evidence?
Select an answer first - 23
An incident responder notices that the /var/log/syslog file has been cleared and then repopulated with only a few entries that appear to be normal system messages. Which anti-forensics technique is being used?
Select an answer first - 24
You are analyzing a Linux system and find a binary that is packed with a custom packer, not a standard one like UPX. The binary is also encrypted, and you cannot easily unpack it. You need to understand its behavior. Which approach is most likely to be effective?
Select an answer first - 25
An incident responder is examining a compromised Linux host and notices that the /var/log/auth.log file has been truncated and replaced with a single line that appears to be a legitimate login entry. Which anti-forensics technique is most likely being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.