Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 2Objective 1

Linux OS Event Log Introduction GLIR Practice Questions (Page 2)

Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
1concept

Questions 6–10

  1. 6expert · hard

    A Linux administrator is configuring a new server and wants to ensure that all OS event logs are captured, including kernel messages, authentication events, and service logs, in a centralized location. The administrator also needs to be able to search logs by time range and service. Which logging setup would best meet these requirements?

    Select an answer first
  2. 7application · medium

    A Linux system is configured to use systemd-journald. An analyst wants to see all logs from the last boot only. Which journalctl option accomplishes this?

    Select an answer first
  3. 8foundation · easy

    During an incident response engagement, an analyst needs to determine which Linux OS event logs can provide evidence of user authentication attempts, service failures, and kernel-level errors. What is the primary purpose of Linux OS event logs in this context?

    Select an answer first
  4. 9expert · hard

    A security team is investigating a breach on a Linux server. The attacker is known to have used a compromised account to log in via SSH. The team needs to determine the exact time of the login and the source IP. However, the system uses both rsyslog and journald. The /var/log/auth.log file is missing, but journald is active. Which approach would yield the most reliable evidence?

    Select an answer first
  5. 10application · medium

    During incident response on a CentOS 7 system, you need to identify when a specific user last executed sudo commands. Which command would you run to query the relevant log?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.