Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 3Objective 3

Overcoming Misdirection Techniques GREM Practice Questions (Page 9)

Part of the Malware Patterns and Obfuscation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
5concepts

Questions 41–44

  1. 41expert · hard

    You are analyzing a malware sample that uses a custom packer. After unpacking, you find that the code contains many junk instructions and opaque predicates. You need to produce a clean, analyzable binary for further static analysis. Which approach is most effective?

    Select an answer first
  2. 42application · medium

    During analysis of a trojan, you find a function that uses an opaque predicate to decide between two paths. One path leads to a decryption routine, the other to a benign-looking function. You determine that the predicate is always true. What should you do to understand the malware's behavior?

    Select an answer first
  3. 43foundation · easy

    What is the primary impact of control flow flattening on program analysis?

    Select an answer first
  4. 44foundation · easy

    When analyzing a malware sample, you encounter a block of instructions that is never reached during execution. What is the most appropriate way to handle this dead code?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GREM

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.