
GIAC Linux Incident Responder
Domain 1Objective 3
Linux File System Fundamentals and Analysis GLIR Practice Questions (Page 1)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 1–5
- 1
What happens to a hard link when the original file it points to is deleted?
Select an answer first - 2
During a forensic investigation, you need to locate a list of user accounts on a compromised Linux system. You also need to find the home directory of a specific user to look for malicious scripts. Which two directories/files would you examine?
Select an answer first - 3
You are analyzing a Linux system where the /home partition is mounted with the noexec option. A user reports that they cannot execute a script from their home directory. What is the most likely cause, and what is the appropriate action?
Select an answer first - 4
A junior analyst reports that a critical configuration file in /etc has permissions of -rw-r--r-- and is owned by root:root. The incident response team needs to modify this file to contain a new threat-intel feed. The analyst is logged in as a user in the 'security' group, which is not root. What is the most appropriate action to allow the analyst to edit the file while maintaining least privilege?
Select an answer first - 5
Which command would you use to display the disk space usage of file systems in a human-readable format?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.