Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 4Objective 2

Linux Threat Hunting and Incident Response GLIR Practice Questions (Page 9)

Part of the Advanced Analysis and Threat Hunting domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 41–45

  1. 41application · medium

    During a memory forensics investigation of a Linux host, you find a suspicious process that is not visible in the process list but is present in the memory dump. Which tool and technique would best help you analyze this hidden process?

    Select an answer first
  2. 42foundation · easy

    What is the primary purpose of a YARA rule?

    Select an answer first
  3. 43expert · hard

    Your organization wants to integrate threat intelligence feeds into your Linux threat hunting process. You have a commercial feed with high-fidelity indicators and a free feed with lower fidelity but broader coverage. You need to minimize false positives while maximizing detection. Which approach would be best?

    Select an answer first
  4. 44application · medium

    Your organization wants to implement a proactive threat hunting program on Linux servers. You have a limited budget and need to start with the highest-impact data sources. Which combination of data sources would provide the best foundation for threat hunting?

    Select an answer first
  5. 45application · medium

    You are configuring Sysmon for Linux on a critical server. You want to detect file creation in /tmp that is followed by execution. Which Sysmon configuration approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.