Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 3Objective 2

Evidence Collection and Mounting GLIR Practice Questions (Page 6)

Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
5concepts

Questions 26–28

  1. 26expert · hard

    You are leading an incident response team. The team needs to collect evidence from a compromised Linux server, but the server is also a production system that cannot be taken offline. You must balance the need for evidence integrity with system availability. Which approach is most appropriate?

    Select an answer first
  2. 27expert · hard

    During an incident response, you need to mount a LVM logical volume that contains the root filesystem of a compromised server. The volume group is not active. You have a forensic image of the physical volume. Which sequence of steps is most appropriate to access the logical volume without altering the evidence?

    Select an answer first
  3. 28expert · hard

    You have a forensic image of a Linux system that used LVM with LUKS encryption on the logical volume. You have the passphrase. You need to mount the filesystem read-only. Which sequence of steps is correct?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GLIR

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.