Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 4Objective 3

Analyzing Malicious RTF Files GREM Practice Questions (Page 5)

Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 21–25

  1. 21application · medium

    An analyst receives a suspicious RTF file from a phishing campaign. The file opens normally in a word processor, but the analyst notices the file size is unusually large for a text-only document. During a quick hex review, the analyst sees the string '\object' near the end of the file. Which next step would most efficiently confirm whether the file contains an embedded OLE object?

    Select an answer first
  2. 22expert · hard

    An analyst is analyzing an RTF file that uses a non-standard obfuscation technique: the control words are encoded in Unicode, and the embedded object is split across multiple groups. The analyst needs to extract the embedded object. Which approach is most effective?

    Select an answer first
  3. 23application · medium

    A security analyst is triaging an RTF file that contains a large number of control words and nested groups. The file is suspected of exploiting a known vulnerability in a word processor's font-parsing routine. The analyst needs to confirm the exploit pattern without executing the file. Which action is most appropriate?

    Select an answer first
  4. 24expert · hard

    A security team is investigating a targeted RTF attack. They have a YARA rule that detects a known CVE-2017-11882 exploit pattern. However, the rule is producing many false positives on benign documents that contain similar formatting. The team needs to reduce false positives while maintaining detection of the exploit. Which approach is most effective?

    Select an answer first
  5. 25expert · hard

    An analyst is examining a malicious RTF that uses multiple layers of obfuscation. The file contains hex-encoded data, then the decoded data is another RTF with an embedded OLE object. The analyst needs to extract the final payload. Which approach is most efficient?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.