Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 3Objective 2

Interactive and Manual Malware Analyses GCED Practice Questions (Page 10)

Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
11concepts

Questions 46–50

  1. 46foundation · easy

    What is the purpose of documentation and reporting in malware analysis?

    Select an answer first
  2. 47expert · hard

    An analyst has completed a thorough interactive analysis of a new ransomware variant and must produce a report for both technical and non-technical stakeholders. The report needs to support detection, containment, and executive decision-making. Which structure best meets these needs?

    Select an answer first
  3. 48application · medium

    An analyst is debugging a malware sample that appears to unpack itself in memory. The analyst sets a breakpoint on the `VirtualAlloc` function and then on `VirtualProtect`. After the breakpoints are hit, the analyst wants to dump the unpacked code from memory for further static analysis. Which tool or technique is most appropriate for this task?

    Select an answer first
  4. 49application · medium

    During interactive static analysis of a suspected trojan, an analyst opens the binary in a disassembler and notices that the import table contains only LoadLibraryA and GetProcAddress. The strings view shows a suspicious URL and a registry key path. What is the most likely reason for the sparse import table, and what should the analyst do next?

    Select an answer first
  5. 50expert · hard

    During dynamic analysis of a banking trojan, an analyst observes that the malware injects code into a legitimate browser process and then communicates with a C2 server over HTTPS. The analyst wants to extract IOCs that would be most useful for network-based detection. Which set of IOCs is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.