Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 4Objective 3

Analyzing Malicious RTF Files GREM Practice Questions (Page 4)

Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 16–20

  1. 16foundation · easy

    What is the purpose of a YARA rule in the context of RTF analysis?

    Select an answer first
  2. 17foundation · easy

    Why is it important to document the analysis process and findings for a malicious RTF file?

    Select an answer first
  3. 18foundation · easy

    Which of the following is a common indicator of a malicious RTF file?

    Select an answer first
  4. 19application · medium

    An incident response team is triaging a batch of RTF files suspected of exploiting a known vulnerability in Microsoft Word's RTF parser. The team wants to quickly identify files that contain the specific exploit pattern without opening them. Which method is most appropriate for this task?

    Select an answer first
  5. 20foundation · easy

    What is a common pattern to look for when detecting a CVE-2017-11882 exploit in an RTF file?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.