GIAC GREM Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: GREM
  • Exam Name/Title: GIAC Reverse Engineering Malware
  • Certification Provider: GIAC
  • Corresponding Certification: GIAC Information Security
  • Exam Questions: 195
  • Updated On: Jun 03, 2026
What does the presence of DllImport attribute indicate in a .NET assembly? (Choose Two)
Correct Answer: A,B Vote an answer
What is the primary purpose of using a disassembler in reverse engineering malware?
Correct Answer: A Vote an answer
When analyzing a PDF file for malicious content, why is it important to examine the file's metadata?
Correct Answer: C Vote an answer
Why is it important to analyze unpacked versions of malware?
Correct Answer: C Vote an answer
Which of the following is the MOST reliable indicator that the payload is unpacked?
Correct Answer: D Vote an answer
Which API calls are commonly used by malware to manipulate processes and inject code?
(Choose two)
Correct Answer: B,C Vote an answer
What is the primary purpose of analyzing loops in a malware sample?
Correct Answer: A Vote an answer
Which of the following methods can be used to analyze a suspicious PDF document? (Choose Two)
Correct Answer: C,D Vote an answer
Which tool is most commonly used to analyze JavaScript embedded within a malicious PDF?
Correct Answer: C Vote an answer
Which technique can be utilized to hide malicious macro code within an Office document?
Correct Answer: B Vote an answer
Which methods are commonly used by malware authors to obfuscate their code? (Choose two)
Correct Answer: B,C Vote an answer
What is the primary advantage of .NET malware for attackers?
Correct Answer: C Vote an answer
Which of the following techniques can be used to defeat code obfuscation in malware?
Correct Answer: D Vote an answer
0
0
0
10