
GIAC Reverse Engineering Malware
Domain 5Objective 2
Unpacking and Debugging Packed Malware GREM Practice Questions (Page 4)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 16–20
- 16
During triage of a suspicious Windows executable, an analyst observes that the .text section has an unusually high entropy value and the section names include .UPX0 and .UPX1. Which conclusion is most directly supported by these observations?
Select an answer first - 17
When performing static analysis on a packed binary, which piece of information is most likely to be hidden or obfuscated and therefore require unpacking to reveal?
Select an answer first - 18
After dumping an unpacked process, what is the primary purpose of rebuilding the import table?
Select an answer first - 19
When stepping through an unpacking stub, why might an analyst use the 'Step Over' (F8) command instead of 'Step Into' (F7)?
Select an answer first - 20
An analyst needs to unpack a malware sample packed with UPX. The goal is to obtain a runnable unpacked executable for further static analysis. Which approach is the most efficient and reliable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.