
GIAC Reverse Engineering Malware
Domain 4Objective 1
Analyzing Malicious Office Macros GREM Practice Questions (Page 9)
Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
11concepts
Questions 41–45
- 41
A user receives a file with a .doc extension, but it is actually a ZIP archive containing XML files and a macro. Which file format is this?
Select an answer first - 42
An analyst is analyzing a macro that uses a long Sleep() call before executing the payload. The macro also checks the system uptime and exits if uptime is less than 10 minutes. What is the most likely purpose of these combined techniques?
Select an answer first - 43
During static analysis of a malicious Word document, an analyst finds VBA code that uses the Evaluate() function with a string built from concatenated substrings. The substrings are stored in reverse order in the code. What is the primary purpose of this technique?
Select an answer first - 44
A malicious macro uses a multi-stage payload delivery: it first writes a file to disk, then uses 'Shell' to execute it, and finally deletes the file. An analyst wants to capture the file before it is deleted. What is the best approach?
Select an answer first - 45
What is the purpose of a macro checking for the presence of a debugger?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.