
GIAC Linux Incident Responder
Domain 3Objective 2
Evidence Collection and Mounting GLIR Practice Questions (Page 2)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
Questions 6–10
- 6
You are documenting the mounting of a forensic image. You have recorded the command, options, timestamp, and hash values. What else should you include to maintain a complete chain of custody?
Select an answer first - 7
During an incident response, you need to mount a suspect filesystem to extract log files. The filesystem contains a partition that was previously mounted read-write. You want to avoid any changes to file access times and ensure no writes occur. Which set of mount options best achieves this?
Select an answer first - 8
You have a forensic image of a Linux system that used a software RAID 1 (mirror) with LUKS encryption on the md device. You have both disk images and the passphrase. You need to mount the filesystem read-only. Which sequence of steps is correct?
Select an answer first - 9
Which mount option prevents the filesystem from updating access timestamps when files are read, thereby preserving metadata during evidence collection?
Select an answer first - 10
An incident responder needs to mount a forensic image of a Linux filesystem to examine its contents. Which mount command ensures the filesystem is mounted read-only?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.