
GIAC Linux Incident Responder
Domain 4Objective 2
Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 6)
Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 26–30
- 26
What is the primary purpose of an incident response playbook?
Select an answer first - 27
An incident responder is investigating a compromised Linux host. They find a systemd service that runs a script from /var/tmp/.cache every time the system boots. The script downloads and executes additional payloads. Which action should be taken FIRST to contain the threat while preserving evidence?
Select an answer first - 28
Your organization receives a threat intelligence feed with a YARA rule that has a high false-positive rate on your Linux servers. You need to integrate the feed without overwhelming your analysts. Which approach is most effective?
Select an answer first - 29
You are investigating a Linux host that was compromised. The attacker modified a system binary, added a new user, and created a systemd service. Which artifact would provide the most reliable evidence of the binary modification?
Select an answer first - 30
A threat intelligence feed provides a list of malicious file hashes and YARA rules. You want to integrate this into your Linux threat hunting process. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.