
GIAC Linux Incident Responder
Domain 2Objective 2
Analyzing Linux Events GLIR Practice Questions (Page 6)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
9concepts
Questions 26–30
- 26
Which tool is used to search and query audit records generated by auditd?
Select an answer first - 27
You are analyzing a compromised Linux host. You have collected the following data: journald logs, syslog files, and auditd records. You need to identify the first malicious action taken by the attacker. Which technique is most effective for this task?
Select an answer first - 28
A log entry in /var/log/syslog shows a timestamp of 'Feb 12 14:30:22' without a year. The system's timezone is UTC+2. You need to convert this to epoch time for correlation with other logs. What additional information do you need?
Select an answer first - 29
An analyst is correlating events from multiple sources to reconstruct a timeline of a suspected intrusion. Which of the following is the MOST reliable approach to ensure accurate correlation?
Select an answer first - 30
You are building a timeline from multiple log sources. You notice that the system's clock was adjusted during the incident (e.g., via NTP or manual change). What is the most important consideration when correlating events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.