GIAC Enterprise Incident Response (GEIR) Free Practice Test
Question 1
For analyzing log data effectively, which command is best suited for sorting and extracting specific information?
Response:
Response:
Correct Answer: C
Question 2
Which Linux directory contains the configuration files for most software packages?
Response:
Response:
Correct Answer: C
Question 3
When responding to a cloud incident, what is the primary purpose of using automated techniques?
Response:
Response:
Correct Answer: A
Question 4
On macOS, where can you find system application logs?
Response:
Response:
Correct Answer: A
Question 5
Which factors should be considered when deploying rapid triage tools across macOS devices in an enterprise?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: C,D
Question 6
Which locations are crucial when examining logs for signs of an attack on macOS?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: B,D
Question 7
Select the tool that is most appropriate for analyzing network traffic to detect potential intrusions in real-time.
Response:
Response:
Correct Answer: A
Question 8
What does the cloud deployment model 'Public Cloud' imply?
Response:
Response:
Correct Answer: C
Question 9
What command in Linux would you use to list all active processes?
Response:
Response:
Correct Answer: B