
GIAC Reverse Engineering Malware
Domain 3Objective 3
Overcoming Misdirection Techniques GREM Practice Questions (Page 9)
Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
5concepts
Questions 41–44
- 41
You are analyzing a malware sample that uses a custom packer. After unpacking, you find that the code contains many junk instructions and opaque predicates. You need to produce a clean, analyzable binary for further static analysis. Which approach is most effective?
Select an answer first - 42
During analysis of a trojan, you find a function that uses an opaque predicate to decide between two paths. One path leads to a decryption routine, the other to a benign-looking function. You determine that the predicate is always true. What should you do to understand the malware's behavior?
Select an answer first - 43
What is the primary impact of control flow flattening on program analysis?
Select an answer first - 44
When analyzing a malware sample, you encounter a block of instructions that is never reached during execution. What is the most appropriate way to handle this dead code?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GREM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.