
GIAC Offensive AI Analyst
Domain 3Objective 1
Malware Fundamentals GOAA Practice Questions (Page 5)
Part of the AI-Enhanced Malware and Deepfakes domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
6concepts
Questions 21–25
- 21
In the malware lifecycle, which stage typically follows the initial delivery of the malicious payload to the target system?
Select an answer first - 22
A security analyst discovers a malicious executable that masquerades as a legitimate PDF viewer. When a user runs it, it installs a backdoor. Which malware category does this describe?
Select an answer first - 23
An analyst runs a malware sample in a controlled virtual machine and monitors its file system, registry, and network activity. Which analysis approach is being used?
Select an answer first - 24
Which stage of the malware lifecycle involves ensuring the malware remains active on the system even after a reboot or user logout?
Select an answer first - 25
A security team is evaluating a new threat intelligence report that describes a malware campaign using exploit kits hosted on compromised websites. The report indicates that the exploit kit targets browser vulnerabilities and delivers a trojan. The team wants to implement a control that reduces the risk of infection from this campaign. Which control is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.