
GIAC Linux Incident Responder
Domain 3Objective 1
Incident Response Triage GLIR Practice Questions (Page 2)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 6–10
- 6
What is the primary purpose of creating a forensic image of a storage device?
Select an answer first - 7
What should be included in triage documentation to ensure reproducibility?
Select an answer first - 8
A Linux server is suspected of being compromised. The responder needs to identify potential evidence sources. Which combination of sources is most appropriate for initial triage?
Select an answer first - 9
A Linux server is suspected of being compromised. You need to identify potential digital evidence sources. Which of the following is a volatile evidence source that should be captured FIRST?
Select an answer first - 10
During an incident, a responder needs to preserve the contents of a Linux server's memory and disk. The server is still running and cannot be taken offline immediately. Which approach best preserves evidence integrity while allowing the server to continue operating?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.