
GIAC Linux Incident Responder
Domain 2Objective 2
Analyzing Linux Events GLIR Practice Questions (Page 2)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
9concepts
Questions 6–10
- 6
What is a key technique in timeline analysis for identifying anomalies?
Select an answer first - 7
Which of the following is an example of correlating events from multiple sources?
Select an answer first - 8
What is the primary goal of event correlation in incident response?
Select an answer first - 9
Which of the following is a common output format for a timeline in forensic analysis?
Select an answer first - 10
You need to analyze a large volume of logs to find all file deletions that occurred on a Linux server during a specific time window. The server has auditd configured with a rule to watch /home. Which command will most efficiently extract the relevant audit records?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.