
GIAC Linux Incident Responder
Domain 4Objective 2
Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 1)
Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 1–5
- 1
In a Linux environment, which activity best exemplifies a proactive threat hunting action?
Select an answer first - 2
During a threat hunt, you notice a process named 'kworker' running from /tmp/.hidden with high CPU usage. The process has no open files and its parent is PID 1. Which step is most appropriate to determine if this is malicious?
Select an answer first - 3
A threat intelligence feed provides a YARA rule for a Linux rootkit. You need to scan a memory dump from a potentially infected host. Which command would you use?
Select an answer first - 4
Which Linux kernel subsystem does auditd use to collect system call and security event information?
Select an answer first - 5
A security team wants to implement proactive threat hunting on their Linux fleet. They have auditd configured on all servers and collect network flow logs. Which activity best exemplifies proactive threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.