Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 3Objective 3

Analyzing Anti-Forensics Techniques GLIR Practice Questions (Page 6)

Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
7concepts

Questions 26–30

  1. 26application · medium

    You are investigating a Linux system where the attacker used 'shred' to delete sensitive files. You need to determine if any remnants of the files remain. Which forensic technique would be most effective for recovering data that may have been overwritten by shred?

    Select an answer first
  2. 27application · medium

    During an incident response on a compromised Linux web server, you find a suspicious file named 'logo.png' in /var/www/html. The file's size is 2 MB, but when you open it in an image viewer, it appears as a small 100x100 pixel image. You suspect data hiding. Which command would most efficiently confirm that additional data is embedded in the file?

    Select an answer first
  3. 28application · medium

    You are analyzing a compromised Linux system and find a file that appears to be a JPEG image but has a suspiciously large size. You suspect the attacker is hiding data. Which technique would best confirm this?

    Select an answer first
  4. 29application · medium

    You are analyzing a Linux system and notice that the /var/log/syslog file has been modified, and there are gaps in the timestamps. You suspect the attacker edited the log to remove entries. Which of the following would be the most reliable way to detect the tampering?

    Select an answer first
  5. 30foundation · easy

    A forensic analyst is investigating a Linux system and finds a file that appears to be a normal text file, but when opened with a hex editor, it contains a hidden message embedded in the least significant bits of the file's data. Which data hiding technique is being used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.