
GIAC Linux Incident Responder
Domain 4Objective 1
Linux Memory and Device Profiling Analysis GLIR Practice Questions (Page 3)
Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
7concepts
Questions 11–15
- 11
A forensic analyst is analyzing a memory dump from a Linux server. The analyst needs to see the command line arguments for all running processes to identify any suspicious commands. Which Volatility plugin would be most appropriate?
Select an answer first - 12
An incident responder needs to acquire memory from a Linux system that is suspected of being compromised. The system is running a custom kernel that is not supported by standard memory acquisition tools. Which approach is the most practical?
Select an answer first - 13
Which memory analysis artifact would you examine to identify a process that has an open network socket?
Select an answer first - 14
A security team is investigating a rootkit on a Linux server. The memory dump shows that the 'sys_call_table' has been modified. The team also finds a suspicious kernel module loaded. Which of the following actions would be the most effective to determine if the module is responsible for the sys_call_table modification?
Select an answer first - 15
Which tool is commonly used to analyze a Linux memory dump to list running processes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.