
GIAC Linux Incident Responder
Domain 1Objective 4
Linux File System Artifacts GLIR Practice Questions (Page 7)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
6concepts
Questions 31–35
- 31
Which tool is commonly used to recover deleted files from an ext3 or ext4 file system?
Select an answer first - 32
You are analyzing a file that was modified by an attacker. The file's atime is newer than its mtime. What does this indicate?
Select an answer first - 33
You are analyzing a disk image and need to view the partition table to identify the layout of the disk. Which command is specifically designed for this purpose?
Select an answer first - 34
You are responding to an incident on a system that uses systemd-journald. The attacker cleared the journal to cover their tracks. However, you need to find evidence of the attacker's activities. Which approach is most likely to yield useful evidence?
Select an answer first - 35
You need to determine which software packages were installed or updated on a Debian-based system during the incident window. Which log file would you examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.