live chatMcAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
Pass4Test 10%OFF Discount Code

GIAC Reverse Engineering Malware - GREM Exam Questions

QUESTION NO: 1
What is the primary goal of behavioral malware analysis?
Correct Answer: A
QUESTION NO: 2
When analyzing .NET malware, which of the following findings would be considered significant?
(Choose Three)
Correct Answer: C,D,E
QUESTION NO: 3
What feature of PDFs can be abused to hide malicious content? (Choose Two)
Correct Answer: A,D
QUESTION NO: 4
You are performing static analysis on a suspicious Windows executable. The file has an unusual section labeled .rsrc and imports numerous suspicious DLLs, such as advapi32.dll. What steps should you take to gather more information? (Choose three)
Correct Answer: A,D,E
QUESTION NO: 5
Which of the following is a common technique used to obfuscate JavaScript?
Correct Answer: D
QUESTION NO: 6
What aspects should be analyzed to determine if a macro in an Office file is self-replicating?
(Choose Two)
Correct Answer: B,D
QUESTION NO: 7
What file structure is analyzed in the static analysis of a Windows executable?
Correct Answer: B
QUESTION NO: 8
Which of the following is a common obfuscation technique used in .NET malware?
Correct Answer: B
QUESTION NO: 9
What techniques are commonly used by attackers in malicious RTF files? (Choose two)
Correct Answer: A,C
QUESTION NO: 10
What is a key indicator that JavaScript code has been obfuscated?
Correct Answer: C
QUESTION NO: 11
What is the primary purpose of analyzing loops in a malware sample?
Correct Answer: B
QUESTION NO: 12
What is the significance of identifying obfuscated code within a macro?
Correct Answer: C
QUESTION NO: 13
You are analyzing a malware sample and notice it uses multiple JMP instructions that lead to dead code segments, making it difficult to follow the actual execution flow. What steps should you take to overcome this misdirection technique? (Choose three)
Correct Answer: B,C,E