
GIAC Linux Incident Responder
Domain 2Objective 1
Linux OS Event Log Introduction GLIR Practice Questions (Page 3)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
1concept
Questions 11–15
- 11
A company runs a critical application on a Linux server. The security team wants to monitor for unauthorized file access attempts. They have auditd available. Which configuration would provide the most comprehensive monitoring with minimal performance impact?
Select an answer first - 12
A Linux administrator is configuring a new server and wants to ensure that all authentication events are logged to a remote SIEM in real time. Which configuration would achieve this?
Select an answer first - 13
A forensic analyst is investigating a Linux system where the attacker modified system time to evade detection. The analyst needs to establish the correct sequence of events. Which log source would be most resistant to time-manipulation and help reconstruct the true timeline?
Select an answer first - 14
An incident responder is examining a compromised Linux server and needs to identify all successful and failed SSH login attempts, including the source IP addresses. Which OS event log file would be the primary source for this information?
Select an answer first - 15
A security analyst is investigating a Linux server that was compromised. The attacker used a valid SSH key to log in. The analyst wants to determine if any other systems were accessed using the same key. Which log would provide the most useful information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.