Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 3Objective 1

Incident Response Triage GLIR Practice Questions (Page 4)

Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
6concepts

Questions 16–20

  1. 16application · medium

    A Linux server in your organization has been flagged by an IDS for suspicious outbound connections. The server hosts a critical database and is not publicly accessible. You are performing an initial assessment. Which factor is MOST important in determining the urgency of this incident?

    Select an answer first
  2. 17foundation · easy

    Why is it important to document triage decisions and actions taken?

    Select an answer first
  3. 18application · medium

    A responder needs to preserve evidence from a compromised Linux server. Which action is essential for maintaining chain of custody?

    Select an answer first
  4. 19expert · hard

    You are documenting a Linux incident response. You have preserved evidence and taken containment actions. You need to write a report that is clear and reproducible. Which of the following is the BEST practice for your documentation?

    Select an answer first
  5. 20foundation · easy

    During incident response triage, what is the primary purpose of prioritizing alerts?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.