
GIAC Linux Incident Responder
Domain 1Objective 4
Linux File System Artifacts GLIR Practice Questions (Page 3)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
6concepts
Questions 11–15
- 11
An attacker gained access to a system and ran several commands. You need to determine if the attacker used sudo to gain root privileges. Which log file would provide this information?
Select an answer first - 12
During an incident response engagement, you discover that an attacker modified a critical configuration file in /etc. The system uses ext4 with default mount options. You need to determine the earliest possible time the file was tampered with. Which timestamp should you examine first?
Select an answer first - 13
You are analyzing a system where the /var directory is mounted on a separate partition. You need to determine if the attacker could have hidden data in the /var partition. Which characteristic of /var makes it a common hiding place?
Select an answer first - 14
You are investigating a system that uses systemd. You need to find the logs from the time of the incident, which occurred two days ago. Which command would you use to access the relevant logs?
Select an answer first - 15
Which command would you use to display a list of currently mounted file systems and their mount points?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.