Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 1Objective 1

Malware Analysis Fundamentals GREM Practice Questions (Page 4)

Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
1concept

Questions 16–20

  1. 16expert · hard

    A security team is analyzing a fileless malware that resides only in memory. The team has a memory image but no executable file. The team needs to extract the malware's code and understand its behavior. Which approach is most effective?

    Select an answer first
  2. 17application · medium

    A security analyst receives a suspicious executable from an internal user who clicked a phishing link. The analyst must determine the executable's capabilities without risking the production network. The analyst has a Windows 10 VM with network access to the internet and a Linux VM with no network access. Which approach best aligns with the goals of malware analysis?

    Select an answer first
  3. 18application · medium

    An organization has been hit by a phishing campaign that delivers a malicious Office document. The incident response team needs to determine the document's capabilities and whether it drops additional malware. Which analysis approach is most appropriate for this scenario?

    Select an answer first
  4. 19application · medium

    During incident response, a team recovers a memory image and a suspicious binary from a compromised host. The team needs to quickly determine if the binary is known malware and what indicators of compromise (IOCs) to search for across the fleet. Which combination of actions best meets this need?

    Select an answer first
  5. 20application · medium

    An incident responder has identified a malicious macro in an Excel spreadsheet. The responder needs to extract the macro code for analysis. Which tool or method is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.