
GIAC Certified Enterprise Defender
Domain 3Objective 2
Interactive and Manual Malware Analyses GCED Practice Questions (Page 8)
Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 36–40
- 36
Which element should be included in a malware analysis report?
Select an answer first - 37
A malware analyst is asked to analyze a sample that is suspected to be a downloader. The analyst has a limited time window and needs to quickly determine what the malware downloads and from where. Which approach is most efficient?
Select an answer first - 38
An analyst is using x64dbg to debug a 64-bit malware sample. The malware is known to use anti-debugging techniques, including the `IsDebuggerPresent` API. What is the most effective way to bypass this check so the malware continues running normally?
Select an answer first - 39
A security team has a malware sample that evades automated sandboxes by checking for the presence of a debugger and delaying execution. The team needs to understand the malware's full behavior. Why is interactive malware analysis more appropriate than fully automated analysis in this case?
Select an answer first - 40
An analyst is executing a ransomware sample in a controlled VM. The analyst wants to observe which files are encrypted and which registry keys are modified. Which tool is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.