
GIAC Linux Incident Responder
Domain 1Objective 2
Linux OS File System Structure GLIR Practice Questions (Page 9)
Part of the Linux Fundamentals and File System Analysis domain, which makes up ~35% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~25–42 in this domain), expect 6–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 41–43
- 41
A forensic image contains a file with permissions -rw-r----- and ownership root:staff. An investigator needs to read the file but is not in the staff group. Which action allows the investigator to read the file without altering the original evidence?
Select an answer first - 42
A server's /var partition is full, causing services to fail. You need to identify which files in /var/log are the largest to free up space. Which command lists the largest files in /var/log?
Select an answer first - 43
A service account needs to read a configuration file in /etc/app/config.yml, but the file is owned by root with permissions 640. The service account is in the 'app' group. Which command makes the file readable by the service account without changing ownership?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.