Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 3Objective 2

Interactive and Manual Malware Analyses GCED Practice Questions (Page 2)

Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
11concepts

Questions 6–10

  1. 6expert · hard

    An analyst is performing dynamic analysis of a trojan that is known to check for the presence of analysis tools (e.g., Wireshark, ProcMon) and alter its behavior if they are detected. The analyst needs to observe the malware's true behavior. Which approach is most effective?

    Select an answer first
  2. 7foundation · easy

    What is the purpose of behavioral observation and logging during malware analysis?

    Select an answer first
  3. 8foundation · easy

    Which tool is commonly used for interactive malware analysis to step through code and set breakpoints?

    Select an answer first
  4. 9foundation · easy

    Which action is part of behavioral observation and logging?

    Select an answer first
  5. 10application · medium

    A malware sample is packed with a custom packer. The analyst has identified the original entry point (OEP) by setting a breakpoint on `VirtualProtect` and observing a `jmp` instruction to a new code section. What is the next best step to obtain a usable unpacked binary for static analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.