
GIAC Certified Enterprise Defender
Domain 3Objective 2
Interactive and Manual Malware Analyses GCED Practice Questions (Page 6)
Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 26–30
- 26
Which technique is used to handle obfuscated malware during interactive analysis?
Select an answer first - 27
A malware analyst receives a suspicious binary and runs `strings` on it. The output shows very few readable strings, and the file's entropy is high. The PE section names are `.UPX0`, `.UPX1`, and `.UPX2`. What should the analyst do next to best understand the binary's functionality?
Select an answer first - 28
A malware analyst is performing dynamic analysis of a sample that is known to download a second-stage payload. The analyst wants to capture the payload and observe the malware's network behavior. Which combination of tools is most appropriate for this task?
Select an answer first - 29
An analyst is analyzing a malware sample that uses a custom packer and contains anti-debugging code that detects software breakpoints by checking for `0xCC` bytes in its own code. The analyst needs to trace the unpacking routine. Which debugging technique is most appropriate to avoid detection?
Select an answer first - 30
What is the purpose of code tracing in malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.