Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Linux Incident Responder

Domain 2Objective 4

Linux Timeline Analysis GLIR Practice Questions (Page 5)

Part of the Event Log Analysis and Timeline Analysis domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 5–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    What is the first step in identifying anomalous activity in a timeline?

    Select an answer first
  2. 22foundation · easy

    Which step is essential when building a super timeline?

    Select an answer first
  3. 23expert · hard

    A timeline shows that a user `alice` logged in at 09:00, then a file in `/home/alice/secret.txt` was accessed at 09:05, and then a process named `curl` made an outbound connection to an external IP at 09:10. The user `alice` is known to be on vacation. What is the most likely conclusion?

    Select an answer first
  4. 24application · easy

    You need to build a super timeline that includes filesystem timestamps, auth.log entries, and process accounting logs. Which tool is best suited to parse all these sources and produce a unified timeline?

    Select an answer first
  5. 25application · medium

    You have a raw disk image from a compromised Linux system. You need to generate a timeline that includes filesystem metadata and also want to incorporate log file entries. Which tool combination is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GLIR” is a trademark of its owner, used for identification only.