
GIAC Reverse Engineering Malware
Domain 5Objective 2
Unpacking and Debugging Packed Malware GREM Practice Questions (Page 1)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 1–5
- 1
An analyst has a malware sample packed with a custom packer that is not recognized by automated unpackers. The analyst needs to unpack the sample. Which approach is most appropriate?
Select an answer first - 2
While debugging a packed binary, the debugger suddenly exits when the malware calls `IsDebuggerPresent`. Which debugging technique is most appropriate to bypass this anti-debugging check?
Select an answer first - 3
Why is it important to use a virtual machine (VM) or a dedicated analysis host when dynamically analyzing packed malware?
Select an answer first - 4
An analyst wants to extract readable strings from a packed binary without executing it. Which tool or technique is most appropriate for this task?
Select an answer first - 5
While debugging a packed malware sample, the analyst notices that the program calls `IsDebuggerPresent` and then `OutputDebugString` with a specific string. The analyst wants to bypass these anti-debugging checks without altering the sample's behavior. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.