
GIAC Linux Incident Responder
Domain 2Objective 2
Analyzing Linux Events GLIR Practice Questions (Page 1)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
9concepts
Questions 1–5
- 1
Which log file commonly contains network connection events?
Select an answer first - 2
An analyst needs to export journald logs from the last 24 hours to a file for analysis. Which command would accomplish this?
Select an answer first - 3
During an incident, you notice that a user account was created at 03:00 UTC, and at 03:05 UTC a new SSH key was added to the root user's authorized_keys file. You need to determine if these events are related and if the account creation was the initial access vector. Which combination of log sources would you correlate to build the most complete timeline?
Select an answer first - 4
An incident responder is building a timeline from multiple log sources. Which of the following is the MOST effective way to identify anomalies in the timeline?
Select an answer first - 5
A server's /var/log/messages file has been rotated and compressed. The incident responder needs to search for a specific error string across all rotated logs. Which command will search the compressed logs without decompressing them to disk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.