- GREM has 66 questions, 3 hours, and a 73% minimum passing score - memorize this ratio.
- The exam mixes multiple-choice with hands-on CyberLive VM tasks, not just theory questions.
- 15 published domains span macros, PDFs, RTF, .NET, obfuscation, and unpacking - know all headings.
- Exam-only registration is $999; retake is $899 after a mandatory 30-day wait.
Quick Facts Snapshot
This page is built to be the single reference you skim the night before your GIAC Reverse Engineering Malware exam. Every number below comes directly from GIAC's published specifications for GREM - no estimates, no borrowed figures from other certifications that happen to share the acronym. If you want the narrative version of these facts with context and reasoning, the GREM Study Guide 2026 walks through how to turn this cheat sheet into a study plan.
| Attribute | Detail |
|---|---|
| Certifying body | GIAC (Global Information Assurance Certification) |
| Question count | 66 questions |
| Time limit | 3 hours |
| Passing score | 73% |
| Question format | Multiple-choice plus hands-on CyberLive VM tasks |
| Delivery | ProctorU remote or Pearson VUE test center (as authorized on attempt) |
| Attempt window | 120 days from activation |
| Exam-only cost | $999 USD (training sold separately) |
| Retake cost | $899, after a 30-day waiting period |
| Practice test | $399 standalone |
| Extension | $479 |
| Validity | 4 years |
| Renewal | 36 CPEs or renewal exam; $499 standard renewal fee |
The 15 Domains at a Glance
GIAC publishes 15 domain headings for the certification exam objectives. Print this list, tape it to your monitor, and check off each one as you drill practice scenarios. A deeper breakdown of what each domain actually tests lives in the GREM Exam Domains 2026 guide.
The Full List
- Domain 1: Analyzing Malicious Office Macros
- Domain 2: Analyzing Malicious PDFs
- Domain 3: Analyzing Malicious RTF Files
- Domain 4: Analyzing Obfuscated Malware
- Domain 5: Behavioral Analysis Fundamentals
- Domain 6: Common Malware Patterns
- Domain 7: Core Reverse Engineering Concepts
- Domain 8: Examining .NET Malware
- Domain 9: Identifying and Bypassing Anti-Analysis Techniques
- Domain 10: Malware Analysis Fundamentals
- Domain 11: Malware Flow Control and Structures
- Domain 12: Overcoming Misdirection Techniques
- Domain 13: Reversing Functions in Assembly
- Domain 14: Static Analysis Fundamentals
- Domain 15: Unpacking and Debugging Packed Malware
Notice the pattern: document-format analysis (macros, PDFs, RTF) sits alongside classic binary reverse engineering (assembly, unpacking, .NET). GREM tests both the "malicious document triage" skillset and the "static/dynamic binary analysis" skillset in the same exam, which is why candidates who only practice one side often underestimate difficulty. For a candid assessment of where people struggle, see How Hard Is the GREM Exam?
Exam Mechanics You Cannot Get Wrong
The exam is a single, web-based, proctored session - there is no separate lab day or second exam. Two mechanics trip up first-time candidates more than anything else:
- Answers lock once submitted. You cannot go back and change a question after you commit an answer, so don't rush-click through easy questions expecting to revisit them.
- Skipped questions can be revisited. If you're unsure, leave it blank and move on - unanswered questions remain editable until you submit or time expires.
The engine includes a built-in calculator and a scratch notepad, which matters for domains like Reversing Functions in Assembly and Malware Flow Control and Structures where you'll be tracking register values, offsets, or loop counters by hand. CyberLive tasks mean some questions drop you into an actual virtual machine to perform a live action - this is not a purely theoretical, click-the-best-answer exam.
Key Takeaway
Practice in a real disassembler or debugger environment before exam day - CyberLive tasks reward muscle memory with tools, not just conceptual recall.
Fees, Retakes, and Timeline
Budget planning matters as much as content review. Here's the exact fee structure:
| Item | Cost | Notes |
|---|---|---|
| Exam-only attempt | $999 USD | Before taxes; training is purchased separately |
| Retake | $899 | Requires 30-day wait after a failed attempt |
| Standalone practice test | $399 | Official GIAC practice exam |
| Attempt extension | $479 | Extends beyond the standard window |
| Renewal fee | $499 | Standard CPE renewal path |
Once your attempt is activated, the clock runs for 120 days - plenty of time if you plan deliberately, tight if you procrastinate. For a full cost breakdown including scenarios like training bundles, see GREM Certification Cost 2026. If you fail, the mandatory 30-day waiting period before a retake is non-negotiable, so treat your first attempt as the one that counts.
Open-Book Rules and What to Bring
GREM is open-book, but the rules are specific and strictly enforced:
- Allowed: hardcopy books, printed notes, and a printed index you assemble yourself.
- Prohibited: internet access, personal electronic references, and any practice-question or answer collections.
This means your prep strategy should include building a physical, indexed reference binder organized by domain - for example, a tabbed section for Analyzing Obfuscated Malware with your own notes on common deobfuscation routines, and another for Unpacking and Debugging Packed Malware with your go-to breakpoint strategies. An indexed binder is faster to search under time pressure than flipping through an entire course book.
Key Takeaway
Build your index while you study, not the week before - a binder you can navigate in seconds is worth more than one with more pages.
Priority Topics by Domain Cluster
Rather than treating all 15 domains as equally weighted unknowns, group them into three functional clusters and prepare each with a different mindset.
Cluster 1: Malicious Document Analysis
Covers Domain 1 (Office Macros), Domain 2 (PDFs), and Domain 3 (RTF Files). These questions test your ability to extract, decode, and interpret embedded scripts and exploit payloads inside common document formats.
- Practice extracting and de-obfuscating VBA macros
- Know common PDF object structures used to hide JavaScript
- Understand RTF object linking tricks used for exploit delivery
Cluster 2: Core Binary Reverse Engineering
Covers Domain 7 (Core Reverse Engineering Concepts), Domain 13 (Reversing Functions in Assembly), Domain 11 (Malware Flow Control and Structures), Domain 8 (.NET Malware), and Domain 15 (Unpacking and Debugging Packed Malware). This cluster is the technical backbone of the exam and where CyberLive tasks are most likely to appear.
- Be fluent reading x86/x64 disassembly and recognizing common function prologues
- Practice identifying packers and stepping through unpacking in a debugger
- Understand .NET-specific reversing differences versus native binaries
Cluster 3: Analysis Methodology and Evasion
Covers Domain 5 (Behavioral Analysis Fundamentals), Domain 6 (Common Malware Patterns), Domain 9 (Anti-Analysis Techniques), Domain 10 (Malware Analysis Fundamentals), Domain 12 (Overcoming Misdirection Techniques), and Domain 14 (Static Analysis Fundamentals). This cluster tests judgment: knowing which analysis method to apply and recognizing when malware is actively resisting you.
- Distinguish static vs. dynamic analysis appropriate to a given sample
- Recognize anti-debugging and anti-VM checks and how to defeat them
- Catalog common misdirection tactics like junk code and API hashing
This clustering approach is more useful than studying domains in numeric order, because it mirrors how a real analyst approaches an unknown sample: triage the delivery mechanism, reverse the core payload, then account for evasion. For candidates comparing this workload against career payoff, Is the GREM Certification Worth It? and GREM Jobs cover who actually hires for this skill set.
Final-Week Review Schedule
In the last stretch before your attempt, structure your remaining hours around the three clusters above rather than re-reading everything linearly.
Document Analysis Refresh
- Re-run macro, PDF, and RTF extraction labs from memory
- Update your indexed binder's document-analysis tab
Binary Reversing Drills
- Time yourself unpacking a sample and reversing key functions
- Review .NET-specific reversing notes and flow-control patterns
Evasion and Methodology
- Drill anti-analysis and misdirection recognition scenarios
- Take the official practice test if you haven't already
Logistics and Light Review
- Confirm ProctorU or Pearson VUE details per your registered attempt
- Skim your binder index only - no new material
For a broader multi-week plan built around this same clustering logic, see the GREM Study Guide 2026. And if you want a data-informed view of how candidates typically perform, GREM Pass Rate 2026 discusses what's publicly known without inventing numbers.
Certification Validity and Renewal
GREM is valid for 4 years from the date you earn it. Before expiration, you have two renewal paths:
- CPE route: Accumulate 36 CPEs and pay the standard $499 renewal fee.
- Renewal examination route: Retake a qualifying exam instead of submitting CPEs.
Plan your CPE activities around ongoing malware analysis work, conference attendance, or further training so the renewal window doesn't sneak up on you. This is also a good moment to revisit whether your GREM is still opening the doors you expected - the GREM Salary Guide 2026 and practice test platform are useful checkpoints for staying current with both the material and the market.
Frequently Asked Questions
No. It combines multiple-choice questions with hands-on CyberLive virtual-machine tasks, so some items require you to actually perform an action inside a live environment rather than just select an answer.
No. The exam is open-book for hardcopy books, printed notes, and a printed index only. Internet access, personal electronic references, and practice-question collections are prohibited.
Skipped questions remain available to revisit before you submit the exam. However, once you submit an answer to a specific question, it cannot be changed.
You have 120 days from activation of your attempt to complete the exam. Your candidate account will show the attempt-specific exam specifications and deadline.
A retake costs $899, and you must wait 30 days after a failed attempt before scheduling the retake. See GREM Passing Score 2026 for exactly what score you need to avoid a retake entirely.