Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 1Objective 3

Static Analysis Fundamentals GREM Practice Questions (Page 1)

Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
11concepts

Questions 1–5

  1. 1foundation · easy

    What type of information is typically found in the Version Info resource of a PE file?

    Select an answer first
  2. 2application · medium

    A malware analyst is examining a suspicious executable and wants to determine what Windows API functions it imports. The analyst opens the file in CFF Explorer and navigates to the import table. Which finding would be most suspicious and warrant further investigation?

    Select an answer first
  3. 3application · medium

    While analyzing a malware sample, an analyst finds a string that reads `sandboxie` and imports for `GetTickCount` and `Sleep`. What is the most likely purpose of these indicators?

    Select an answer first
  4. 4expert · hard

    An analyst extracts strings from a malware sample and finds the string `http://192.168.1.100/update` and the API name `WinExec`. The sample also contains the string `cmd.exe /c del %s`. What is the most likely functionality?

    Select an answer first
  5. 5foundation · easy

    In a PE file, which field specifies the address where execution begins?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.