
GIAC Linux Incident Responder
Domain 2Objective 4
Linux Timeline Analysis GLIR Practice Questions (Page 5)
Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 21–25
- 21
What is the first step in identifying anomalous activity in a timeline?
Select an answer first - 22
Which step is essential when building a super timeline?
Select an answer first - 23
A timeline shows that a user `alice` logged in at 09:00, then a file in `/home/alice/secret.txt` was accessed at 09:05, and then a process named `curl` made an outbound connection to an external IP at 09:10. The user `alice` is known to be on vacation. What is the most likely conclusion?
Select an answer first - 24
You need to build a super timeline that includes filesystem timestamps, auth.log entries, and process accounting logs. Which tool is best suited to parse all these sources and produce a unified timeline?
Select an answer first - 25
You have a raw disk image from a compromised Linux system. You need to generate a timeline that includes filesystem metadata and also want to incorporate log file entries. Which tool combination is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.