
GIAC Certified Enterprise Defender
Domain 3Objective 1
Malware Analysis Concepts and Basic Analysis Techniques GCED Practice Questions (Page 7)
Part of the Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 31–35
- 31
A malware analyst needs to analyze a sample that uses anti-VM techniques, such as checking for specific registry keys and processes. The analyst has a VM that is configured with default settings. Which action would most likely improve the success of the analysis?
Select an answer first - 32
A malware analyst is analyzing a sample that creates a service, modifies a registry key, and sends data to an external IP. The analyst needs to produce a report that includes both host-based and network-based indicators. The analyst has already captured the behavior in a sandbox. Which set of artifacts should be included in the report?
Select an answer first - 33
A security analyst receives a suspicious executable from an employee. The analyst needs to quickly determine whether the file is likely malicious before deciding to detonate it in a sandbox. The analyst runs `strings` on the file and sees URLs, registry key paths, and a unique embedded string that also appears in a public malware report. Which next step best confirms the file's association with the known malware family?
Select an answer first - 34
A malware sample is observed creating a file in the Windows Startup folder and adding a registry Run key. The analyst needs to determine the persistence mechanism and whether the malware also communicates over the network. Which analysis step would provide the most direct evidence of both persistence and network activity?
Select an answer first - 35
A security team is reviewing a suspicious PDF file. Static analysis reveals a JavaScript snippet that calls an external URL. The team wants to identify the malware family and related campaign. Which indicator should be prioritized for searching threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.