
GIAC Reverse Engineering Malware
Domain 5Objective 1
Examining .NET Malware GREM Practice Questions (Page 9)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 41–45
- 41
Which indicator suggests that a .NET executable is packed?
Select an answer first - 42
An analyst is using dnSpy to inspect a .NET malware sample and wants to identify all external methods the malware calls. Which metadata table should the analyst focus on?
Select an answer first - 43
An analyst is examining a .NET malware sample that uses a commercial obfuscator. The obfuscator has renamed all methods and fields to random characters, encrypted all strings, and flattened the control flow. The analyst has identified the decryption routine and can decrypt the strings. However, the control flow flattening makes it difficult to understand the logic. Which approach is most effective for deobfuscating the control flow?
Select an answer first - 44
Which characteristic is TRUE of managed .NET code compared to unmanaged native code?
Select an answer first - 45
Which of the following is a key component of a .NET assembly that stores information about the types, members, and references used by the assembly?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.