Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 3Objective 1

Incident Response Triage GLIR Practice Questions (Page 2)

Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    What is the primary purpose of creating a forensic image of a storage device?

    Select an answer first
  2. 7foundation · easy

    What should be included in triage documentation to ensure reproducibility?

    Select an answer first
  3. 8application · medium

    A Linux server is suspected of being compromised. The responder needs to identify potential evidence sources. Which combination of sources is most appropriate for initial triage?

    Select an answer first
  4. 9application · medium

    A Linux server is suspected of being compromised. You need to identify potential digital evidence sources. Which of the following is a volatile evidence source that should be captured FIRST?

    Select an answer first
  5. 10application · medium

    During an incident, a responder needs to preserve the contents of a Linux server's memory and disk. The server is still running and cannot be taken offline immediately. Which approach best preserves evidence integrity while allowing the server to continue operating?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.