
GIAC Linux Incident Responder
Domain 1Objective 2
Linux OS File System Structure GLIR Practice Questions (Page 4)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 16–20
- 16
What is a mount point in Linux?
Select an answer first - 17
Which type of file in Linux is represented by the first character 'l' in the output of 'ls -l'?
Select an answer first - 18
During an incident response, you discover that a compromised process is writing logs to /var/log/custom.log, but the /var partition is full. You need to quickly identify which filesystem is mounted at /var and how much space is available. Which command provides the most direct answer?
Select an answer first - 19
You suspect an attacker mounted an external filesystem over /var/log to hide log entries. Which command would you run to confirm the presence of a separate filesystem mounted at /var/log?
Select an answer first - 20
You need to find all files under /home that are owned by a specific user and have been modified in the last 7 days. Which find command is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.