
GIAC Reverse Engineering Malware
Domain 3Objective 1
Common Malware Patterns GREM Practice Questions (Page 8)
Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 36–40
- 36
A malware analyst is examining a sample that checks for the presence of a debugger by calling IsDebuggerPresent and also queries the registry for VMware-specific keys. If both checks pass (no debugger, no VMware), the malware proceeds to its main payload. Which defense evasion pattern is this sample using?
Select an answer first - 37
A malware sample checks for the presence of a debugger using the IsDebuggerPresent API and also uses a custom packing routine. Which defense evasion pattern does this represent?
Select an answer first - 38
Which of the following is a common persistence mechanism that relies on Windows service control manager?
Select an answer first - 39
Which of the following is a characteristic of using email as a data exfiltration method?
Select an answer first - 40
Which of the following is the best example of a structural pattern that a malware analyst would identify during static analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.