
GIAC Reverse Engineering Malware
Domain 5Objective 1
Examining .NET Malware GREM Practice Questions (Page 8)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 36–40
- 36
Which tool is specifically designed to decompile .NET assemblies into readable C# source code for analysis?
Select an answer first - 37
Which tool is specifically designed to monitor process creation, registry changes, and file system activity during dynamic analysis of malware?
Select an answer first - 38
A .NET malware sample has been obfuscated with a tool that renames all methods to random strings and inserts junk code. The analyst wants to understand the malware's functionality. What is the most useful first step?
Select an answer first - 39
Which of the following is a common .NET obfuscation technique that transforms the original control flow into a complex switch-based state machine?
Select an answer first - 40
A .NET malware sample uses the 'System.Reflection' namespace to load an assembly from a byte array and invoke a method. What is the malware likely doing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.