Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 4Objective 2

Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 10)

Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 46–50

  1. 46application · medium

    Your incident response playbook for a Linux server compromise includes steps to identify persistence mechanisms. During an incident, you find a suspicious cron job that runs a script from /tmp. According to the playbook, what is the next best step?

    Select an answer first
  2. 47foundation · easy

    Which Linux tool is commonly used to capture a memory dump for forensic analysis?

    Select an answer first
  3. 48foundation · easy

    Which Linux command-line tool is commonly used to capture network packets for analysis?

    Select an answer first
  4. 49expert · hard

    During a Linux incident response, you find a suspicious process running from /tmp. The process has a deleted binary, and the /tmp directory is cleared on reboot. You need to preserve the process's memory for analysis. Which action would best preserve the evidence?

    Select an answer first
  5. 50foundation · easy

    Which Linux system component is commonly abused to achieve persistence by creating a service that starts automatically at boot?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GLIR

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.