
GIAC Reverse Engineering Malware
Domain 4Objective 2
Analyzing Malicious PDFs GREM Practice Questions (Page 3)
Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 11–15
- 11
A malware analyst wants to automate the extraction of JavaScript from a large batch of PDF files. Which approach is most suitable?
Select an answer first - 12
While analyzing a malicious PDF, an analyst notices that the JavaScript code uses hexadecimal escapes and string concatenation to build function names. What is the primary purpose of this technique?
Select an answer first - 13
Which vulnerability class is commonly exploited by malicious PDFs that use malformed font files?
Select an answer first - 14
In a PDF file, which structure is the first line of the file and indicates the version of the PDF specification being used?
Select an answer first - 15
A security team is analyzing a PDF that was found on a compromised system. The PDF has a valid header and trailer, but the cross-reference table is incomplete. The team suspects that the PDF may be using incremental updates to hide malicious objects. They also notice that the PDF contains a JavaScript action that uses a known exploit. The team needs to determine the full extent of the malicious content. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.