
GIAC Linux Incident Responder
Domain 1Objective 2
Linux OS File System Structure GLIR Practice Questions (Page 1)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 1–5
- 1
You need to check if a specific filesystem is mounted with the 'noexec' option to prevent execution of binaries. Which command would show the mount options for that filesystem?
Select an answer first - 2
You are investigating a suspicious symbolic link in /tmp that points to /etc/shadow. What is the primary security risk of this symbolic link?
Select an answer first - 3
A security analyst needs to grant a developer read and write access to a log file, but the developer should not be able to execute it. The file is currently owned by root:root with permissions 644. Which command achieves this?
Select an answer first - 4
A forensic analyst is examining a mounted read-only image. They need to read a file that has permissions 600 and is owned by root. The analyst has sudo privileges but must not alter the image. Which approach allows reading the file without modifying the image?
Select an answer first - 5
While investigating a compromised system, you find a file in /dev that appears to be a normal text file but is actually a device file. Which command would you use to confirm the file type?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.