
GIAC Linux Incident Responder
Domain 1Objective 3
Linux File System Fundamentals and Analysis GLIR Practice Questions (Page 4)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 16–20
- 16
You need to identify the type of a suspicious file (e.g., whether it is a script, binary, or archive) during an investigation. Which command is best suited for this task?
Select an answer first - 17
During an incident response, you need to determine which file system contains a specific file located at /var/log/auth.log. The /var directory is a separate partition. Which command would provide the most direct answer?
Select an answer first - 18
During an investigation, you find that a critical system library /lib/x86_64-linux-gnu/libc.so.6 has been replaced with a symbolic link to /tmp/malicious.so. The original library file is still present at /lib/x86_64-linux-gnu/libc-2.31.so. Which statement about the system's behavior is correct?
Select an answer first - 19
You are investigating a system where an attacker has deleted a critical log file. You have a forensic image of the file system. You know the file was recently deleted and you have its inode number. Which tool would be most likely to recover the file's content?
Select an answer first - 20
You are analyzing a compromised system and find a directory with a large number of hard links to a single file. You need to understand the relationship between these files. Which command would show you the inode number and link count for all files in that directory?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.