Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 3Objective 2

Analyzing Obfuscated Malware GREM Practice Questions (Page 8)

Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 36–40

  1. 36application · medium

    An analyst is reviewing a sample that uses a suspicious API call pattern. The sample calls VirtualAlloc, then writes to the allocated memory, and then calls VirtualProtect to change the memory protection to PAGE_EXECUTE_READ. What does this pattern most likely indicate?

    Select an answer first
  2. 37application · medium

    During dynamic analysis of a suspected obfuscated sample, the malware detects that it is running inside a virtual machine and refuses to execute its payload. The analyst needs to observe the malicious behavior. Which adjustment is most likely to allow the sample to run?

    Select an answer first
  3. 38expert · hard

    A malware sample uses a two-stage unpacking process. The first stage is a simple XOR loop, but the second stage uses AES with a key that is derived from the system's volume serial number. The analyst is analyzing the sample in a VM. The sample detects the VM and exits before the second stage. The analyst needs to extract the final payload. Which approach is most effective?

    Select an answer first
  4. 39application · medium

    An analyst is analyzing a sample that uses a custom packer. The sample checks the system uptime and exits if uptime is less than 10 minutes, likely to evade sandboxes. The analyst wants to unpack the sample in a controlled environment. What is the most effective approach?

    Select an answer first
  5. 40application · medium

    A security analyst is triaging a suspicious executable. Static analysis shows a single section with entropy of 7.9 and no imported APIs. The file is small and has a suspicious entry point that jumps to the middle of the section. What is the most likely conclusion?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.