
GIAC Linux Incident Responder
Domain 1Objective 2
Linux OS File System Structure GLIR Practice Questions (Page 6)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 26–30
- 26
An incident responder needs to preserve evidence from a live system. They want to copy the contents of /var/log to an external drive without altering the original files' timestamps. Which command should be used?
Select an answer first - 27
Which of the following is a common temporary file location that an incident responder should check for suspicious files?
Select an answer first - 28
You need to determine whether a file's permissions were changed after it was last modified. Which two timestamps would you compare?
Select an answer first - 29
What information is stored in an inode?
Select an answer first - 30
Which command is used to display currently mounted filesystems and their mount points?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.