
GIAC Linux Incident Responder
Domain 2Objective 4
Linux Timeline Analysis GLIR Practice Questions (Page 1)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 1–5
- 1
You are correlating events from a Linux system that uses local time (CST, UTC-6) for its logs, but the filesystem timestamps are stored in UTC. You notice an SSH login at 01:30 CST and a file creation at 07:30 UTC. What is the relationship between these events?
Select an answer first - 2
Why is timeline analysis considered a critical step in Linux incident response?
Select an answer first - 3
You are building a super timeline from a compromised system. You have a filesystem timeline from `fls`/`mactime`, syslog, and process accounting. The filesystem timeline shows a file creation at 12:00:00, but the syslog shows a related event at 12:00:05. However, the process accounting log shows the process that created the file started at 11:59:55. What is the most accurate interpretation?
Select an answer first - 4
What is the purpose of applying a time range filter to a timeline?
Select an answer first - 5
Which combination of events would be most useful for correlating to identify a potential data exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.