
GIAC Reverse Engineering Malware
Domain 5Objective 2
Unpacking and Debugging Packed Malware GREM Practice Questions (Page 6)
Part of the Advanced Malware Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
Questions 26–30
- 26
In manual unpacking with a debugger, what is the purpose of setting a breakpoint at the Original Entry Point (OEP)?
Select an answer first - 27
After successfully unpacking a malware sample, what is the most effective way to understand its core functionality?
Select an answer first - 28
A malware sample checks the BIOS serial number and the presence of a specific kernel driver to detect a virtual machine. The analyst needs to bypass these checks to continue debugging. Which approach is most effective?
Select an answer first - 29
An analyst is triaging a large number of binaries and needs to quickly identify which ones are likely packed. Which combination of static indicators is most indicative of packing?
Select an answer first - 30
An analyst is manually unpacking a malware sample. After tracing the unpacking stub, the analyst reaches a `jmp` instruction that jumps to a region of memory that appears to be the original code. What should the analyst do next to obtain a usable unpacked binary?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GREM” is a trademark of its owner, used for identification only.