Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 5Objective 2

Unpacking and Debugging Packed Malware GREM Practice Questions (Page 2)

Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
9concepts

Questions 6–10

  1. 6application · medium

    An analyst has a packed malware sample and needs to determine the original entry point (OEP) without executing the sample. Which static technique can help estimate the OEP?

    Select an answer first
  2. 7foundation · medium

    What is a common limitation of automated unpacking tools?

    Select an answer first
  3. 8foundation · medium

    Which tool is commonly used to fix the import table of a dumped unpacked executable?

    Select an answer first
  4. 9application · easy

    An analyst has a malware sample that is packed with a common packer. The analyst wants to use an automated unpacker to extract the unpacked code. Which tool is specifically designed for automated unpacking of common packers?

    Select an answer first
  5. 10expert · hard

    A malware sample uses a combination of anti-debugging techniques, including checking the `PEB->BeingDebugged` flag and using the `NtQueryInformationProcess` API. The analyst wants to bypass both checks. Which approach is most efficient?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.