Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 1Objective 3

Linux File System Fundamentals and Analysis GLIR Practice Questions (Page 2)

Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    During an incident response investigation, you discover a suspicious file in /tmp. The file's inode number is 524289, and it has a link count of 2. You check /home/user and find another file with the same inode number. Which command would you use to confirm that both filenames reference the same underlying data without modifying the file system?

    Select an answer first
  2. 7application · medium

    You are investigating a Linux system where an attacker created a symbolic link from /etc/passwd to /tmp/evil_passwd. What is the most likely impact on the system, and what is the appropriate immediate action?

    Select an answer first
  3. 8application · medium

    You are investigating a Linux server where an attacker is suspected of using a bind mount to hide malicious files. You notice that /etc appears to contain an unusual file that is not present in the original /etc directory. Which command would be most effective for identifying the bind mount?

    Select an answer first
  4. 9application · medium

    During an incident response investigation, you need to examine files on a mounted USB drive that was attached to a compromised Linux server. The server's /etc/fstab does not contain an entry for this device. You have successfully mounted the device at /mnt/evidence. Which command will provide the most useful information about the file system type and mount options currently in effect for this device?

    Select an answer first
  5. 10expert · medium

    You are analyzing a compromised system and need to determine if a specific directory is a separate mount point or just a subdirectory. You have access to the /proc/mounts file. Which approach would be most reliable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.