Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 4Objective 1

Analyzing Malicious Office Macros GREM Practice Questions (Page 11)

Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
11concepts

Questions 51–55

  1. 51foundation · easy

    Which tool is commonly used to monitor file system and registry changes during dynamic analysis of a macro?

    Select an answer first
  2. 52foundation · easy

    In which Office application would a file with the .xlsm extension be opened?

    Select an answer first
  3. 53application · medium

    While analyzing a malicious Word document, an analyst finds a VBA module that contains a function named 'DecodeString' that takes a string and performs XOR operations. The function is called from multiple procedures. What is the most likely purpose of this function?

    Select an answer first
  4. 54foundation · easy

    What is the purpose of using 'variable renaming' as an obfuscation technique in malicious macros?

    Select an answer first
  5. 55foundation · easy

    Which of the following is a common anti-analysis technique used by malicious macros to detect virtual machines?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.