
GIAC Reverse Engineering Malware
Domain 1Objective 3
Static Analysis Fundamentals GREM Practice Questions (Page 9)
Part of the Malware Analysis Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
11concepts
Questions 41–45
- 41
Which hashing algorithm produces a 256-bit digest and is commonly used for malware identification?
Select an answer first - 42
What is the primary purpose of the TrID tool in file identification?
Select an answer first - 43
While performing static analysis on a malware sample, an analyst notices the string 'IsDebuggerPresent' in the import table and the string 'sandbox' in the .rdata section. The PE header's compilation timestamp is set to a date 10 years in the future. What is the most likely purpose of these combined indicators?
Select an answer first - 44
An analyst is comparing two malware samples from the same campaign. Sample A imports CreateRemoteThread, WriteProcessMemory, and VirtualAllocEx. Sample B imports only LoadLibraryA and GetProcAddress, and its import table is otherwise empty. Both samples have similar strings and the same compilation timestamp. What is the most likely relationship between the two samples?
Select an answer first - 45
A malware analyst is examining a PE file's import table and finds that it imports `IsDebuggerPresent`, `CheckRemoteDebuggerPresent`, and `NtQueryInformationProcess`. What is the most likely purpose of these imports?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.