Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 4Objective 3

Analyzing Malicious RTF Files GREM Practice Questions (Page 8)

Part of the Document and File Analysis domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 5–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A security team is investigating a series of RTF files that exploit a known vulnerability in a word processor. The team has a YARA rule that matches the exploit pattern, but it is producing false positives on legitimate files. The team needs to refine the rule to reduce false positives without missing true positives. Which approach is most effective?

    Select an answer first
  2. 37application · medium

    A malicious RTF file contains an embedded OLE object that is itself an RTF file. The inner RTF contains a macro. An analyst needs to extract the inner RTF and analyze the macro. Which tool or method is most effective for this nested extraction?

    Select an answer first
  3. 38expert · hard

    A malware analyst is analyzing an RTF with an embedded macro that appears to download a second-stage payload. The macro is heavily obfuscated and uses API calls that are not visible in static analysis. The analyst needs to determine the full behavior of the macro. Which approach is most effective?

    Select an answer first
  4. 39foundation · easy

    What tool can be used to extract macros from an RTF file?

    Select an answer first
  5. 40application · medium

    During an incident response, an analyst finds an RTF file that contains an embedded OLE object. The object appears to be a Microsoft Equation Editor component, which is known to be associated with CVE-2017-11882. The analyst needs to confirm the exploit and determine the payload's behavior. Which sequence of actions provides the most reliable confirmation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.