
GIAC Certified Enterprise Defender
Domain 3Objective 1
Malware Analysis Concepts and Basic Analysis Techniques GCED Practice Questions (Page 6)
Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 26–30
- 26
An analyst is analyzing a malware sample that communicates with a command-and-control server using HTTP. The analyst has captured network traffic. Which of the following are valid indicators of compromise that can be extracted from the network traffic? Select all that apply.
Select an answer first - 27
Which of the following is an example of an indicator of compromise (IOC) that can be used to detect malware on a system?
Select an answer first - 28
An analyst must determine whether a suspicious binary contains encrypted configuration data. The analyst has not yet executed the binary. Which approach would be most appropriate to identify the presence of encrypted data?
Select an answer first - 29
A suspicious executable is found on a server. The analyst wants to determine if the file is packed or obfuscated before running it. Which static analysis technique would best reveal this?
Select an answer first - 30
An analyst is running a malware sample in a sandbox. The malware is known to check for the presence of analysis tools and change its behavior if it detects them. The analyst needs to observe the malware's true behavior. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.