
GIAC Linux Incident Responder
Domain 4Objective 2
Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 10)
Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 46–50
- 46
Your incident response playbook for a Linux server compromise includes steps to identify persistence mechanisms. During an incident, you find a suspicious cron job that runs a script from /tmp. According to the playbook, what is the next best step?
Select an answer first - 47
Which Linux tool is commonly used to capture a memory dump for forensic analysis?
Select an answer first - 48
Which Linux command-line tool is commonly used to capture network packets for analysis?
Select an answer first - 49
During a Linux incident response, you find a suspicious process running from /tmp. The process has a deleted binary, and the /tmp directory is cleared on reboot. You need to preserve the process's memory for analysis. Which action would best preserve the evidence?
Select an answer first - 50
Which Linux system component is commonly abused to achieve persistence by creating a service that starts automatically at boot?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GLIR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.