
GIAC Linux Incident Responder
Domain 3Objective 2
Evidence Collection and Mounting GLIR Practice Questions (Page 3)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
Questions 11–15
- 11
During an incident response, you need to collect evidence from a running system. You have limited time and must prioritize. Which data should you collect first?
Select an answer first - 12
During an incident response, you collect a memory dump and then create a disk image. You record the hash values of both. Which principle of evidence collection does this primarily support?
Select an answer first - 13
When encountering an LVM logical volume during evidence collection, what is the correct approach to mount it read-only?
Select an answer first - 14
Which of the following should be recorded when documenting a mounting procedure for forensic evidence?
Select an answer first - 15
You are examining a forensic image of a Linux filesystem. You need to mount it read-only to avoid any changes. However, the filesystem has a journal that may be replayed by the kernel when mounted. Which mount option should you use to prevent journal replay?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.