
GIAC Reverse Engineering Malware
Domain 1Objective 2
Behavioral Analysis Fundamentals GREM Practice Questions (Page 8)
Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
10concepts
Questions 36–40
- 36
An automated sandbox report for a malware sample shows that it performs a DNS query for 'malicious.com' and then connects to 'malicious.com' on port 8080. The report also shows that the malware sends a POST request with data that appears to be base64-encoded. Which finding is most indicative of data exfiltration?
Select an answer first - 37
When monitoring file system activity, which action would you flag as suspicious?
Select an answer first - 38
An analyst is using Process Monitor to observe a malware sample. The analyst filters for 'Path' contains 'AppData' and sees that the malware creates a file named 'settings.ini' in the AppData\Roaming folder. The analyst also sees that the malware reads a file named 'config.dat' from the same folder. What is the most likely purpose of the 'settings.ini' file?
Select an answer first - 39
Which element is essential to include in a structured behavioral analysis report?
Select an answer first - 40
An analyst is documenting the behavior of a banking trojan. The analyst observed that the malware creates a file named 'config.ini' in the %APPDATA% directory, modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to point to the malware, and sends HTTP POST requests to a domain that is not associated with the bank. Which finding should be prioritized in the report as the most critical indicator of malicious intent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.