
GIAC Reverse Engineering Malware
Domain 1Objective 2
Behavioral Analysis Fundamentals GREM Practice Questions (Page 7)
Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
10concepts
Questions 31–35
- 31
What does an unexpected DNS query to a domain that does not resolve to a known service suggest?
Select an answer first - 32
A security analyst needs to observe the behavior of a suspected trojan downloader in an isolated VM. The analyst must capture the initial DNS query and subsequent HTTP request to the C2 domain, but the corporate policy requires that no traffic leave the analysis lab. Which configuration should the analyst use?
Select an answer first - 33
Which registry key modification is commonly used by malware to achieve persistence?
Select an answer first - 34
An analyst submits a sample to an automated sandbox. The report shows that the sample creates a service named 'LegitService' with a binary path of 'C:\ProgramData\svc.exe', and then the service makes an HTTP request to a domain that is 24 hours old. Which finding is most suspicious?
Select an answer first - 35
What is a primary advantage of using an automated sandbox for malware analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.