
GIAC Reverse Engineering Malware
Domain 3Objective 3
Overcoming Misdirection Techniques GREM Practice Questions (Page 6)
Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
5concepts
Questions 26–30
- 26
You are analyzing a malware sample that uses a technique to hide its true API calls by including many fake API calls in the import table and using a custom resolver. You need to determine which APIs are actually used. Which method is most reliable?
Select an answer first - 27
You are analyzing a malware sample that uses a combination of dead code and opaque predicates. You have identified the dead code and the predicates, but you need to automate the deobfuscation process for a large binary. Which approach is most scalable?
Select an answer first - 28
What is control flow flattening?
Select an answer first - 29
Which of the following is a systematic approach to deobfuscating malware that uses opaque predicates?
Select an answer first - 30
You are analyzing a botnet client that uses control flow flattening. The binary has a large dispatcher that uses a state variable to jump between basic blocks. You want to understand the command-and-control logic. What is the most effective way to reconstruct the original control flow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.