
GIAC Reverse Engineering Malware
Domain 2Objective 1
Core Reverse Engineering Concepts GREM Practice Questions (Page 1)
Part of the Core Reverse Engineering Concepts domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
1concept
Questions 1–5
- 1
A malware analyst is analyzing a sample that uses a rootkit to hide its presence. The analyst wants to identify the rootkit's kernel-mode components. Which approach is most effective?
Select an answer first - 2
During analysis of a Windows executable, an analyst notices that the import table contains only a few functions such as LoadLibraryA and GetProcAddress. The rest of the API calls appear to be resolved at runtime. What does this observation suggest about the malware's behavior?
Select an answer first - 3
Which methodology is commonly used as a first step in reverse engineering an unknown malware sample?
Select an answer first - 4
A security team has captured a malicious document that drops a binary when opened. The team wants to analyze the binary without triggering the document's exploit. Which approach is most appropriate?
Select an answer first - 5
A malware analyst is reverse engineering a trojan that uses anti-debugging techniques. The analyst wants to bypass the anti-debugging checks to analyze the unpacked payload in a debugger. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.