Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Offensive AI Analyst

Domain 3Objective 1

Malware Fundamentals GOAA Practice Questions (Page 4)

Part of the AI-Enhanced Malware and Deepfakes domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    A user receives an email with an attachment that, when opened, installs malware. Which delivery mechanism does this describe?

    Select an answer first
  2. 17application · medium

    A company's security team discovers that a user's machine is sending sensitive documents to an external server. The user had installed a free 'system cleaner' tool that, in addition to its legitimate functions, collects and exfiltrates data. Which malware type best describes this tool?

    Select an answer first
  3. 18application · medium

    A malware analyst needs to determine whether a suspicious executable communicates with an external server. The analyst has a controlled sandbox environment with network monitoring. Which approach would be most effective for this task?

    Select an answer first
  4. 19application · medium

    During an incident response engagement, an analyst discovers that a malicious binary created a Windows service named 'LegitUpdate' that runs at system startup. The service executable is located in a temporary directory. The analyst also finds a scheduled task that runs the same binary every hour. Which two persistence mechanisms are being used by the malware?

    Select an answer first
  5. 20expert · hard

    A security team is investigating a malware outbreak. The initial infection vector is believed to be a drive-by download from a compromised website. The malware is a trojan that uses a custom packer and anti-sandboxing. The team needs to identify the C2 server and understand the malware's persistence mechanisms. Which combination of analysis techniques would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.