
GIAC Linux Incident Responder
Domain 2Objective 3
Analyzing Linux Application Events GLIR Practice Questions (Page 1)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
Questions 1–5
- 1
Which of the following is an indicator of malicious application behavior?
Select an answer first - 2
Which of the following is the primary source for application event data on a modern Linux system using systemd?
Select an answer first - 3
A database server's application log shows a series of unexpected crashes at 02:00, 02:05, and 02:10. The system's journald shows that the database process was killed by SIGKILL at those exact times. The application log also shows a "memory allocation failure" just before each crash. Which additional data source would most directly help you determine if this was a malicious attack or a resource issue?
Select an answer first - 4
A security analyst notices that a web application's log contains an entry with a `user-agent` string that is a long base64-encoded blob, and the request is a `POST` to `/upload` with a large payload. The analyst suspects data exfiltration. Which additional log source would provide the most direct evidence of the data being transferred out of the network?
Select an answer first - 5
Which of the following application behaviors is most likely to indicate a security incident rather than a routine error?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.