Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 4Objective 2

Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 6)

Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    What is the primary purpose of an incident response playbook?

    Select an answer first
  2. 27application · medium

    An incident responder is investigating a compromised Linux host. They find a systemd service that runs a script from /var/tmp/.cache every time the system boots. The script downloads and executes additional payloads. Which action should be taken FIRST to contain the threat while preserving evidence?

    Select an answer first
  3. 28expert · hard

    Your organization receives a threat intelligence feed with a YARA rule that has a high false-positive rate on your Linux servers. You need to integrate the feed without overwhelming your analysts. Which approach is most effective?

    Select an answer first
  4. 29application · medium

    You are investigating a Linux host that was compromised. The attacker modified a system binary, added a new user, and created a systemd service. Which artifact would provide the most reliable evidence of the binary modification?

    Select an answer first
  5. 30application · medium

    A threat intelligence feed provides a list of malicious file hashes and YARA rules. You want to integrate this into your Linux threat hunting process. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.