
GIAC Reverse Engineering Malware
Domain 4Objective 1
Analyzing Malicious Office Macros GREM Practice Questions (Page 8)
Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
11concepts
Questions 36–40
- 36
An analyst is analyzing a macro that uses a custom function to decode strings. The analyst has identified the decoding algorithm but the macro also uses dynamic code evaluation with the 'Eval' function. The analyst needs to extract the final payload URL. What is the most efficient approach?
Select an answer first - 37
In VBA, what is the purpose of a 'Module'?
Select an answer first - 38
An analyst is examining a malicious .docm file and extracts the document metadata using oledump. The metadata shows the author as "John Doe" and the last saved by as "Jane Smith". The creation time is 2023-05-01 and the modification time is 2023-05-02. What can the analyst infer from this metadata?
Select an answer first - 39
What is the main purpose of dynamic analysis of a malicious macro?
Select an answer first - 40
What type of artifact might be embedded in an Office document to provide additional clues about its purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.