Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 1Objective 1

Malware Analysis Fundamentals GREM Practice Questions (Page 5)

Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
1concept

Questions 21–25

  1. 21application · medium

    A security analyst at a mid-sized company receives an alert from the EDR about a suspicious PowerShell command that downloaded a binary from a file-sharing site. The analyst needs to determine whether the binary is malicious and what it does, but the endpoint is still in production and cannot be taken offline. Which approach best aligns with the goals of malware analysis in this incident-response context?

    Select an answer first
  2. 22application · medium

    A malware analyst is analyzing a trojan that is known to download additional payloads. The analyst wants to identify the command-and-control (C2) server addresses. Which analysis technique would be most effective for this purpose?

    Select an answer first
  3. 23application · medium

    A security team is investigating a malware infection that is spreading through a network share. The team needs to identify the malware's propagation method to contain the spread. Which analysis technique would provide the most direct evidence?

    Select an answer first
  4. 24application · medium

    During an incident response, an analyst finds a suspicious executable on a server. The analyst needs to determine if the executable is malware and what it does, but the server is critical and cannot be taken offline. Which action is most appropriate?

    Select an answer first
  5. 25application · medium

    A malware analyst is examining a suspicious PDF file that is believed to exploit a vulnerability in a PDF reader. The analyst needs to determine the exploit's payload. Which analysis approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.