
GIAC Linux Incident Responder
Domain 3Objective 3
Analyzing Anti-Forensics Techniques GLIR Practice Questions (Page 7)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 31–33
- 31
A system administrator suspects that an attacker used a secure erase tool to wipe a specific file's contents before the system was taken offline. Which of the following is the most likely tool used for this purpose?
Select an answer first - 32
You are investigating a Linux system where the attacker tampered with the system logs. You have a forensic image, but the logs were edited. You also have a remote log server that received logs from the system. However, the remote log server has a gap in the logs for the same time period. Which conclusion is most likely?
Select an answer first - 33
During an incident, you find a script on a compromised Linux host that is heavily obfuscated. The script uses variable names like '${IFS}' and 'eval' to hide its true purpose. You need to understand what the script does. Which approach is most effective for analyzing this obfuscated script?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.