
GIAC Linux Incident Responder
Domain 3Objective 1
Incident Response Triage GLIR Practice Questions (Page 8)
Part of the Incident Response and Evidence Handling domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 36–40
- 36
A security team receives three alerts: (1) a failed SSH login on a development server, (2) a successful login from an unknown IP on a domain controller, and (3) a high volume of outbound traffic from a web server. Which alert should be prioritized FIRST during triage?
Select an answer first - 37
A security operations center receives multiple alerts. The team has limited staff and must triage efficiently. Which approach best supports triage goals?
Select an answer first - 38
A responder is documenting triage actions. Which element is essential for maintaining a clear chain of custody?
Select an answer first - 39
You are triaging multiple Linux incidents. Incident 1: A web server is defaced. Incident 2: A database server has a failed login attempt from an unknown IP. Incident 3: A development server has a high CPU load. Which incident should be prioritized?
Select an answer first - 40
Which step is typically the FIRST in the incident response triage process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.