
GIAC Reverse Engineering Malware
Domain 1Objective 1
Malware Analysis Fundamentals GREM Practice Questions (Page 3)
Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
1concept
Questions 11–15
- 11
A security analyst is analyzing a piece of malware that is suspected of stealing credentials from a web browser. The analyst wants to identify the specific APIs the malware uses to access browser data. Which static analysis technique would be most useful?
Select an answer first - 12
A security team is analyzing a keylogger that captures keystrokes and sends them to a remote server. The team needs to identify the keystroke logging mechanism and the exfiltration destination. Which combination of techniques is most effective?
Select an answer first - 13
A security team is analyzing a document with a macro that downloads a payload. The team wants to extract the macro and the URL it contacts without executing the document. Which approach is most appropriate?
Select an answer first - 14
Which statement best describes the primary goal of malware analysis in the context of incident response?
Select an answer first - 15
A malware analyst is analyzing a sample that is known to use anti-debugging techniques. The analyst needs to bypass these techniques to analyze the malware's behavior. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.