
GIAC Linux Incident Responder
Domain 3Objective 2
Evidence Collection and Mounting GLIR Practice Questions (Page 1)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
Questions 1–5
- 1
You are collecting evidence from a compromised Linux server. You have already captured memory and network connections. Which of the following should you collect next according to the order of volatility?
Select an answer first - 2
You are documenting the evidence collection process. Which of the following should be recorded to ensure the chain of custody is complete?
Select an answer first - 3
You are documenting the mounting of a forensic image for a court case. You have recorded the exact command, the options used, and the timestamp. Which additional piece of information is most important to include for chain of custody?
Select an answer first - 4
You are documenting the mounting of a forensic image. You have recorded the command, options, and timestamp. What else should you record to ensure the process is reproducible by another analyst?
Select an answer first - 5
You are documenting the evidence collection process for a legal case. The defense attorney questions the integrity of the evidence. Which documentation would best support the chain of custody?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.