Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 4Objective 3

Analyzing Malicious RTF Files GREM Practice Questions (Page 3)

Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 11–15

  1. 11expert · hard

    A security team needs to create a YARA rule to detect a family of malicious RTF files. The family uses a common header, followed by a variable-length obfuscated blob, and then a fixed footer. The obfuscation method varies between samples, but the footer is always the same. The team wants to minimize false positives while detecting all samples. Which YARA rule design is most effective?

    Select an answer first
  2. 12application · medium

    A malware analyst is examining an RTF document that contains an embedded OLE object with a macro. The analyst needs to determine the macro's behavior without executing the document on a production system. Which approach is most appropriate?

    Select an answer first
  3. 13foundation · easy

    What is a common obfuscation technique used in malicious RTF files?

    Select an answer first
  4. 14application · medium

    A security team is analyzing a malicious RTF document that uses obfuscation to hide its payload. The analyst notices that the RTF contains many control words like '\ul', '\b', and '\i' interspersed with hex-encoded data. The hex-encoded data appears to be a second RTF document. Which approach would best deobfuscate and extract the embedded RTF content?

    Select an answer first
  5. 15application · medium

    During analysis of a suspicious RTF file, an analyst identifies an '\object' control word followed by a large hex blob. The analyst wants to determine if the embedded object is a malicious executable or a benign document. Which tool would be most effective for this task?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.