
GIAC Linux Incident Responder
Domain 1Objective 3
Linux File System Fundamentals and Analysis GLIR Practice Questions (Page 8)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 36–38
- 36
A Linux administrator notices that a file in /etc has the permission string -rw-r--r-- and is owned by root:root. The administrator needs to allow a specific user 'alice' to edit this file without giving her root access or changing the file ownership. What is the most appropriate solution?
Select an answer first - 37
Which command displays detailed inode metadata for a file, including inode number, file type, permissions, and timestamps?
Select an answer first - 38
A junior analyst is investigating a potential privilege escalation. They find a file in /usr/local/bin with permissions -rwsr-xr-x and owned by root:root. They believe this is a setuid root binary that could be exploited. What is the most important next step in their analysis?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.