
GIAC Linux Incident Responder
Domain 4Objective 2
Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 3)
Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 11–15
- 11
You are analyzing a memory dump from a Linux server that was compromised. You suspect a kernel rootkit. Which technique would be most effective in detecting it?
Select an answer first - 12
Which of the following is a key advantage of analyzing a memory dump compared to only examining files on disk?
Select an answer first - 13
What is the primary purpose of Sysmon for Linux?
Select an answer first - 14
Your organization has an incident response playbook for Linux compromise. During an active incident, you discover a new systemd service that was created minutes ago. According to best practices, what should the playbook instruct you to do FIRST?
Select an answer first - 15
You are updating your incident response playbook for Linux. You need to balance the need for thorough evidence collection with the need to contain an active ransomware outbreak. Which approach best balances these competing priorities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.