
GIAC Reverse Engineering Malware
Domain 5Objective 1
Examining .NET Malware GREM Practice Questions (Page 10)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 46–50
- 46
A malware analyst is examining a binary that has both managed and unmanaged code. The managed code is written in C# and uses the .NET Framework, while the unmanaged code is a native DLL that is loaded via P/Invoke. Which statement accurately describes the relationship between these two types of code?
Select an answer first - 47
What is a critical safety measure when setting up a dynamic analysis environment for .NET malware?
Select an answer first - 48
Which tool is commonly used to unpack a packed .NET executable by dumping the managed assembly from memory?
Select an answer first - 49
A security analyst receives a file that is detected as .NET malware, but opening it in dnSpy shows only a small stub with a call to an unmanaged function. The file has a large overlay section. What is the most likely situation, and what should the analyst do next?
Select an answer first - 50
An analyst is analyzing a .NET malware sample that uses a custom string encryption routine. The analyst has identified the decryption method and wants to recover all plaintext strings statically. What is the most efficient approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.