
GIAC Reverse Engineering Malware
Domain 4Objective 2
Analyzing Malicious PDFs GREM Practice Questions (Page 4)
Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 16–20
- 16
A malware analyst needs to extract JavaScript from a PDF that uses FlateDecode compression. Which tool is specifically designed to decompress and extract JavaScript from PDF objects?
Select an answer first - 17
Which PDF object type is used to embed JavaScript code that executes when the PDF is opened?
Select an answer first - 18
An analyst is analyzing a PDF that has a valid header and trailer but the cross-reference table is missing. The analyst suspects that the PDF may be using a technique where the cross-reference table is intentionally omitted to hinder analysis. Which tool or method would be most effective to reconstruct the object structure?
Select an answer first - 19
An analyst is examining a PDF and notices that the cross-reference table is missing or corrupted, but the PDF still opens in a reader. What does this indicate?
Select an answer first - 20
A security team is analyzing a PDF that evades their static analysis tool. The tool reports no JavaScript, but the PDF opens and shows a login prompt. The team suspects the PDF is malicious. They notice the PDF uses object streams and a malformed cross-reference table. What is the most effective next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.