Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 4Objective 2

Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 2)

Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 6–10

  1. 6application · medium

    During a forensic investigation, you find a file in /etc/cron.d/ that is not owned by root and has world-writable permissions. The file contains a command that downloads a script from a remote server. What does this indicate?

    Select an answer first
  2. 7expert · hard

    You are developing a YARA rule to detect a Linux malware family that uses a unique encryption key in its configuration. The key is stored as a string in the binary, but it is obfuscated with XOR. You have a sample of the malware. Which approach would be most effective for creating a rule?

    Select an answer first
  3. 8application · medium

    During a threat hunt, you capture network traffic from a Linux server. You see repeated connections to an external IP on port 4444, with small payloads sent every 60 seconds. The server also has an established connection to an internal database server. What is the most likely scenario?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a strong indicator of lateral movement on a Linux network?

    Select an answer first
  5. 10expert · hard

    You are investigating a Linux host that was used to pivot to other hosts in the network. You have network logs showing SSH connections from this host to multiple internal IPs. You also have threat intelligence indicating the host was compromised. Which evidence would best confirm that the SSH connections were malicious lateral movement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.