
GIAC Reverse Engineering Malware
Domain 1Objective 1
Malware Analysis Fundamentals GREM Practice Questions (Page 6)
Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
1concept
Questions 26–28
- 26
During an incident response, an analyst discovers a suspicious file on a compromised host. The analyst needs to determine if the file is malware and understand its capabilities, but the organization has a policy that prohibits executing unknown binaries on the corporate network. Which analysis approach should the analyst use first?
Select an answer first - 27
A malware analyst is tasked with analyzing a new ransomware sample. The analyst has limited time and needs to produce actionable indicators for the SOC to block the malware across the network. Which combination of analysis goals should the analyst prioritize?
Select an answer first - 28
A malware analyst is analyzing a botnet client that uses domain generation algorithms (DGAs) to find its C2 server. The analyst needs to predict future C2 domains to block them. Which analysis approach is most appropriate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GREM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.