
GIAC Linux Incident Responder
Domain 1Objective 2
Linux OS File System Structure GLIR Practice Questions (Page 8)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 36–40
- 36
You suspect that an attacker mounted a hidden filesystem over /opt. Which command shows all currently mounted filesystems and their mount points?
Select an answer first - 37
A user reports that they cannot find a file they saved in their home directory. You suspect the file was accidentally placed in /root instead of /home/user. Which directory is the standard location for regular users' home directories?
Select an answer first - 38
An analyst finds a suspicious file /tmp/evil.sh and a link /home/user/evil.sh that points to it. You want to preserve the original file's content while removing the link. Which action achieves this?
Select an answer first - 39
A system administrator needs to find a directory that will be cleared on reboot and is intended for temporary files. Which directory is the correct choice?
Select an answer first - 40
You need to find all files on a filesystem that have more than one hard link, which could indicate potential hidden backdoors. Which command would you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.