
GIAC Certified Enterprise Defender
Domain 3Objective 1
Malware Analysis Concepts and Basic Analysis Techniques GCED Practice Questions (Page 2)
Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 6–10
- 6
An analyst is executing a ransomware sample in a sandbox. The analyst wants to identify which files the ransomware encrypts and whether it attempts to delete shadow copies. Which tool would provide the most comprehensive view of these file system activities?
Select an answer first - 7
During dynamic analysis, a malware sample is observed to create a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which two behaviors should be documented as the most critical indicators?
Select an answer first - 8
Which statement correctly distinguishes static analysis from dynamic analysis of malware?
Select an answer first - 9
During malware analysis, an analyst finds a suspicious string in the binary that appears to be a domain name used for command-and-control communication. How is this string best classified?
Select an answer first - 10
After analyzing a malware sample, an analyst has identified a unique domain, a file hash, and a registry key that the malware creates. Which of these indicators is most useful for detecting the malware on other hosts in the environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.