
GIAC Linux Incident Responder
Domain 3Objective 1
Incident Response Triage GLIR Practice Questions (Page 10)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 46–48
- 46
After completing triage on a Linux server, the responder must document the findings. What is the most important element to include for reproducibility?
Select an answer first - 47
You are responding to a Linux incident and need to identify potential digital evidence sources. Which of the following are valid evidence sources that should be considered for preservation? Select all that apply.
Select an answer first - 48
An incident responder is assessing a potential breach. The only indicator is a single unusual outbound connection from a database server. The server is not business-critical, but it contains customer data. The responder must decide whether to escalate the incident. Which factor should be most influential in the escalation decision?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.