
GIAC Linux Incident Responder
Domain 3Objective 2
Evidence Collection and Mounting GLIR Practice Questions (Page 5)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
5concepts
Questions 21–25
- 21
You are mounting a forensic image of a filesystem that was originally mounted with the 'noatime' option. You want to ensure that no writes occur during your examination. Which mount option is essential?
Select an answer first - 22
A forensic image contains an encrypted LUKS partition. What is the first step to access the data without compromising integrity?
Select an answer first - 23
Why is it important to mount a forensic image read-only rather than read-write?
Select an answer first - 24
You are mounting a forensic image of a filesystem that has a hardware RAID controller. The image was created by imaging each physical disk separately. You need to reconstruct the logical volume to mount it read-only. Which approach is most appropriate?
Select an answer first - 25
You are documenting the mounting procedure for a forensic image. Which information is essential to record to maintain a clear chain of custody and reproducibility?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.