
GIAC Linux Incident Responder
Domain 2Objective 1
Linux OS Event Log Introduction GLIR Practice Questions (Page 1)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
1concept
Questions 1–5
- 1
A forensic analyst is building a timeline of a Linux system compromise. The analyst has access to the systemd journal, which contains entries from multiple services. Which journalctl command would allow the analyst to view only authentication-related messages?
Select an answer first - 2
A security team is responding to a breach on a Linux server. The attacker is known to have deleted /var/log/auth.log and /var/log/syslog. The team needs to reconstruct the attacker's activities. Which combination of log sources would provide the most reliable evidence despite the deleted files?
Select an answer first - 3
An analyst is investigating a Linux system where an attacker is suspected of clearing evidence. Which log file, if present, would contain records of successful and failed login attempts that might have been overlooked?
Select an answer first - 4
A forensic investigator is examining a Linux system and needs to determine which users were logged in at the time of a security incident. Which OS event log or command would provide the most accurate historical record of user sessions?
Select an answer first - 5
A Linux administrator needs to ensure that authentication logs are preserved across reboots and are not lost when the system is powered off. Which configuration ensures this persistence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.