Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 3Objective 1

Common Malware Patterns GREM Practice Questions (Page 3)

Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 11–15

  1. 11expert · hard

    A security operations center (SOC) is investigating a compromised host that is using DNS tunneling for C2. The SOC wants to block the C2 traffic without disrupting legitimate DNS services. Which approach would be most effective?

    Select an answer first
  2. 12application · medium

    An incident responder finds that an attacker moved from one workstation to a server by using a stolen NTLM hash to authenticate and then created a scheduled task on the server to execute a payload. Which lateral movement pattern is this?

    Select an answer first
  3. 13expert · hard

    An incident response team is responding to a ransomware attack that spread laterally using pass-the-hash and scheduled tasks. The team wants to contain the spread while preserving forensic evidence. Which action should they take FIRST?

    Select an answer first
  4. 14expert · hard

    A malware analyst is analyzing a sample that uses a scheduled task for persistence. The scheduled task runs a PowerShell script that downloads and executes a payload. The analyst also finds that the sample uses a UAC bypass to run with elevated privileges. Which combination of persistence and privilege escalation techniques is the sample using?

    Select an answer first
  5. 15application · medium

    During a forensic review, an analyst finds that a low-privileged process successfully created a new local administrator account. The process did not exploit any known vulnerability. Which privilege escalation pattern most likely explains this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.