
GIAC Reverse Engineering Malware
Domain 5Objective 3
Identifying and Bypassing Anti-Analysis Techniques GREM Practice Questions (Page 5)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
Questions 21–25
- 21
You are analyzing a malware sample that uses multiple anti-debugging techniques: it checks the PEB BeingDebugged flag, uses NtQueryInformationProcess, and also performs timing checks. You need to bypass all of them to observe the sample's behavior in a debugger. Which approach is most comprehensive?
Select an answer first - 22
A malware sample uses the cpuid instruction to check for the 'hypervisor present' bit and refuses to run if it detects a VM. You are analyzing it in a VMware Workstation VM and need it to execute. Which action is most likely to allow the sample to run?
Select an answer first - 23
A malware sample is observed to check the presence of a file named `C:\windows\system32\vmguest.dll` during execution. Which anti-analysis technique is this an indicator of?
Select an answer first - 24
Which of the following is a common method to bypass anti-debugging checks that rely on the `BeingDebugged` flag in the Process Environment Block (PEB)?
Select an answer first - 25
Which of the following is a common indicator that a malware sample is using an anti-VM technique?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GREM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.