
GIAC Linux Incident Responder
Domain 1Objective 3
Linux File System Fundamentals and Analysis GLIR Practice Questions (Page 3)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 11–15
- 11
You are investigating a system where an attacker may have mounted a hidden file system. You want to see all currently mounted file systems, including those that might be hidden from normal view. Which command would provide the most comprehensive list?
Select an answer first - 12
You are investigating a potential data exfiltration incident. You notice that a large amount of data is being written to a directory that appears to be on the root file system. You want to determine if this directory is actually a separate mount point with its own file system. Which command would provide the most direct evidence of this?
Select an answer first - 13
During a Linux incident response, you need to locate system-wide configuration files that apply to all users. Which directory in the standard Linux file system hierarchy is the primary location for such files?
Select an answer first - 14
You are analyzing a file that was deleted by an attacker. You have a forensic image of the file system. You know the inode number of the deleted file from a directory entry that was recovered. Which tool would be most effective in attempting to recover the file's content?
Select an answer first - 15
You are performing forensic analysis on a compromised server. You find a file with a very high link count (e.g., 15). You need to determine if this is a sign of malicious activity or a normal condition. Which investigation step would be most informative?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.