
GIAC Reverse Engineering Malware
Domain 5Objective 3
Identifying and Bypassing Anti-Analysis Techniques GREM Practice Questions (Page 2)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
Questions 6–10
- 6
When configuring a dynamic analysis sandbox to handle malware that checks for VM artifacts, which setting is most likely to help bypass those checks?
Select an answer first - 7
Which of the following is a common technique used to defeat obfuscation in malware?
Select an answer first - 8
While statically analyzing a malware binary in IDA Pro, you encounter a function that appears to contain a large block of code that is never executed because a preceding conditional jump always takes the same path. The code block contains many instructions that do not affect the program's logic. What is the best way to handle this during analysis?
Select an answer first - 9
When performing static analysis on a malware sample that uses string encryption, which technique is most effective for extracting meaningful strings?
Select an answer first - 10
A malware sample uses the NtQueryInformationProcess API with ProcessDebugPort to detect if it is being debugged. You are using x64dbg to analyze it. Which method is most effective to bypass this specific check?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.