
GIAC Linux Incident Responder
Domain 2Objective 3
Analyzing Linux Application Events GLIR Practice Questions (Page 6)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
Questions 26–30
- 26
A custom application writes logs in a mixed format: some lines are syslog-style, some are JSON, and some are plain text. The analyst needs to extract all error events from the last hour. Which approach is most robust?
Select an answer first - 27
Which log file on a typical Linux system records authentication events such as login attempts?
Select an answer first - 28
In a syslog message, which field identifies the facility that generated the log entry?
Select an answer first - 29
A custom application writes logs in the following format: "2023-10-05 14:23:45, user=jdoe, action=file_upload, file=/tmp/upload.zip, size=1048576". You need to extract all file uploads by user jdoe that are larger than 1 MB. Which command-line approach is most efficient?
Select an answer first - 30
A web application's log shows a successful login from a user account at 10:00 UTC, followed by a series of requests to /admin/settings at 10:05 UTC. The system's auditd logs show that the web server process spawned a shell (e.g., /bin/sh) at 10:06 UTC. Which conclusion is most strongly supported by this correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.