
GIAC Reverse Engineering Malware
Domain 5Objective 2
Unpacking and Debugging Packed Malware GREM Practice Questions (Page 5)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 21–25
- 21
Which technique is commonly used to bypass anti-VM checks in malware?
Select an answer first - 22
Which combination of characteristics is most indicative of a packed executable?
Select an answer first - 23
Which tool is specifically designed to automatically unpack executables packed with UPX?
Select an answer first - 24
When analyzing an unpacked binary, which indicator is most useful for quickly identifying the malware's capabilities?
Select an answer first - 25
An analyst has a packed malware sample and needs to extract configuration data (e.g., C2 URLs) before unpacking. The sample is packed with a custom packer that does not have a known automated unpacker. Which static technique is most likely to reveal the configuration data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.