
GIAC Reverse Engineering Malware
Domain 5Objective 2
Unpacking and Debugging Packed Malware GREM Practice Questions (Page 2)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 6–10
- 6
An analyst has a packed malware sample and needs to determine the original entry point (OEP) without executing the sample. Which static technique can help estimate the OEP?
Select an answer first - 7
What is a common limitation of automated unpacking tools?
Select an answer first - 8
Which tool is commonly used to fix the import table of a dumped unpacked executable?
Select an answer first - 9
An analyst has a malware sample that is packed with a common packer. The analyst wants to use an automated unpacker to extract the unpacked code. Which tool is specifically designed for automated unpacking of common packers?
Select an answer first - 10
A malware sample uses a combination of anti-debugging techniques, including checking the `PEB->BeingDebugged` flag and using the `NtQueryInformationProcess` API. The analyst wants to bypass both checks. Which approach is most efficient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.