Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 3Objective 2

Evidence Collection and Mounting GLIR Practice Questions (Page 5)

Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
5concepts

Questions 21–25

  1. 21application · medium

    You are mounting a forensic image of a filesystem that was originally mounted with the 'noatime' option. You want to ensure that no writes occur during your examination. Which mount option is essential?

    Select an answer first
  2. 22foundation · easy

    A forensic image contains an encrypted LUKS partition. What is the first step to access the data without compromising integrity?

    Select an answer first
  3. 23foundation · easy

    Why is it important to mount a forensic image read-only rather than read-write?

    Select an answer first
  4. 24expert · hard

    You are mounting a forensic image of a filesystem that has a hardware RAID controller. The image was created by imaging each physical disk separately. You need to reconstruct the logical volume to mount it read-only. Which approach is most appropriate?

    Select an answer first
  5. 25application · medium

    You are documenting the mounting procedure for a forensic image. Which information is essential to record to maintain a clear chain of custody and reproducibility?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.