Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Reverse Engineering Malware

Domain 5Objective 2

Unpacking and Debugging Packed Malware GREM Practice Questions (Page 5)

Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
9concepts

Questions 21–25

  1. 21foundation · medium

    Which technique is commonly used to bypass anti-VM checks in malware?

    Select an answer first
  2. 22foundation · medium

    Which combination of characteristics is most indicative of a packed executable?

    Select an answer first
  3. 23foundation · medium

    Which tool is specifically designed to automatically unpack executables packed with UPX?

    Select an answer first
  4. 24foundation · medium

    When analyzing an unpacked binary, which indicator is most useful for quickly identifying the malware's capabilities?

    Select an answer first
  5. 25application · medium

    An analyst has a packed malware sample and needs to extract configuration data (e.g., C2 URLs) before unpacking. The sample is packed with a custom packer that does not have a known automated unpacker. Which static technique is most likely to reveal the configuration data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.