
GIAC Reverse Engineering Malware
Domain 4Objective 1
Analyzing Malicious Office Macros GREM Practice Questions (Page 11)
Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
11concepts
Questions 51–55
- 51
Which tool is commonly used to monitor file system and registry changes during dynamic analysis of a macro?
Select an answer first - 52
In which Office application would a file with the .xlsm extension be opened?
Select an answer first - 53
While analyzing a malicious Word document, an analyst finds a VBA module that contains a function named 'DecodeString' that takes a string and performs XOR operations. The function is called from multiple procedures. What is the most likely purpose of this function?
Select an answer first - 54
What is the purpose of using 'variable renaming' as an obfuscation technique in malicious macros?
Select an answer first - 55
Which of the following is a common anti-analysis technique used by malicious macros to detect virtual machines?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.