- The Passing Score: 73% Explained
- How the 66-Question Format Shapes What You Need to Know
- Which Domains Actually Drive Your Score
- CyberLive Tasks and the Passing Threshold
- Registration, Retakes, and the 120-Day Clock
- Mapping Study Time to the 73% Target
- Open-Book Rules and Their Effect on Score Strategy
- FAQ
- GIAC sets the GREM passing score at 73% across 66 questions in a 3-hour proctored exam.
- The exam mixes multiple-choice items with hands-on CyberLive virtual-machine tasks - both count toward your score.
- You get 120 days from activation to sit the exam, and a failed attempt requires a 30-day wait before retaking.
- Retakes cost $899; the original exam-only attempt is $999 before taxes, separate from FOR610 training.
The Passing Score: 73% Explained
If you're searching for a single number, here it is: GIAC sets the minimum passing score for GIAC Reverse Engineering Malware (GREM) at 73%. That threshold applies to the full 66-question exam, delivered in a single 3-hour, web-based, proctored sitting. There's no separate cut score per domain and no partial-credit curve published by GIAC - you either clear 73% across the whole exam or you don't.
What makes this number tricky to plan around isn't the math - it's the scope behind it. GREM draws from 15 distinct content domains covering everything from malicious Office macros to unpacking techniques, and a 66-question exam has to sample all of that territory in a fairly compressed set of items. That means every question carries more relative weight than you'd see on a longer certification exam, and a handful of misses in unfamiliar domains can be the difference between passing and a mandatory 30-day retake wait.
How the 66-Question Format Shapes What You Need to Know
GREM's exam engine combines traditional multiple-choice questions with CyberLive virtual-machine tasks - practical exercises where you interact with a live environment rather than just selecting an answer from a list. This dual format has a direct effect on how you should interpret the 73% target: you're not just being tested on recall of concepts, you're being tested on whether you can actually execute reverse engineering workflows under time pressure.
Three hours for 66 questions works out to roughly 2.7 minutes per item on average, but that average is misleading. Multiple-choice questions on core terminology or concept identification can usually be answered in well under a minute. CyberLive tasks - where you might be asked to identify a packed binary's behavior, trace a control flow structure, or extract an indicator from a malicious document - can eat several minutes each. Time management across question types is one of the most underrated factors in clearing the passing score, because running out of time on later questions costs you points just as surely as answering incorrectly.
Key Takeaway
Treat the exam as two sub-skills, not one: fast, accurate multiple-choice recall, and slower, methodical hands-on analysis. Budget your three hours accordingly rather than pacing evenly.
Because submitted answers cannot be changed once entered, but skipped questions can be revisited, a sound in-exam strategy is to flag anything you're unsure about, keep moving, and return to flagged items only after you've secured the questions you know cold. This preserves time for the CyberLive tasks that tend to be the most time-intensive.
Which Domains Actually Drive Your Score
GIAC publishes 15 certification-objective domains for GREM, and each one is fair game on exam day. There's no officially disclosed weighting per domain, so the safest assumption is that every domain can appear, and under-preparing in any single one creates a gap that could tip you below 73%.
Domain 7: Core Reverse Engineering Concepts
This domain underpins nearly everything else on the exam. If your grasp of foundational reverse engineering theory is shaky, it will show up as missed points across multiple other domains too.
- Understand disassembly versus decompilation and when each is appropriate
- Be fluent in the terminology GIAC uses for describing binary structure
Domain 15: Unpacking and Debugging Packed Malware
Packed samples are a staple of real-world malware analysis, and this domain tests whether you can identify packing indicators and manually or semi-automatically unpack a binary.
- Recognize common packer signatures and entropy patterns
- Practice debugger-assisted unpacking workflows, not just theory
Domain 9: Identifying and Bypassing Anti-Analysis Techniques
Anti-debugging, anti-VM, and anti-disassembly tricks are heavily represented in modern malware, and GIAC expects candidates to recognize and work around them.
- Know the common API calls and flags malware checks to detect a sandbox
- Practice bypassing at least one anti-debug trick hands-on, not just reading about it
Other domains - Analyzing Malicious Office Macros, Analyzing Malicious PDFs, Analyzing Malicious RTF Files, Examining .NET Malware, Malware Flow Control and Structures, Overcoming Misdirection Techniques, Reversing Functions in Assembly, Static Analysis Fundamentals, Behavioral Analysis Fundamentals, Common Malware Patterns, Analyzing Obfuscated Malware, and Malware Analysis Fundamentals - round out the full 15. Each represents a chunk of the FOR610 curriculum and a plausible source of exam questions. For a section-by-section walkthrough of what to study in each, the GREM Exam Domains 2026 guide maps out preparation priorities domain by domain.
CyberLive Tasks and the Passing Threshold
The CyberLive component is what separates GREM from purely multiple-choice certification exams, and it's also where candidates most often lose points they didn't expect to lose. Because these tasks are hands-on and interactive, there's no way to "guess and move on" the way you might with a multiple-choice item - either you can perform the analysis step or you can't.
The practical implication for your passing-score strategy is straightforward: don't treat CyberLive prep as optional or secondary to reading FOR610 material. If a meaningful share of the 66 questions are practical tasks, and you can only handle the conceptual ones, you're mathematically capping your own score below 73% before you even sit down. Time in a real analysis environment - a debugger, a disassembler, a controlled malware sandbox - is not optional preparation; it's core to clearing the bar.
Registration, Retakes, and the 120-Day Clock
Understanding the passing score in isolation isn't enough - the mechanics around your attempt affect how much margin you have to hit it. Here's what GIAC's published pricing and policies mean for your planning:
| Item | Detail |
|---|---|
| Exam-only attempt | $999 USD before taxes (training purchased separately) |
| Retake fee | $899 |
| Attempt extension | $479 |
| Standalone official practice test | $399 |
| Time to complete | 120 days from activation |
| Retake waiting period | 30 days after a failed attempt |
The 120-day activation window matters because it's tempting to register before you're ready and "study into" the deadline. Given that a failed attempt triggers a mandatory 30-day wait and an $899 retake fee, it's more cost-effective to delay activation until you're confidently testing above 73% on practice material than to rush in and gamble on a first attempt. For the full cost picture including training options, see the GREM Certification Cost breakdown.
Delivery happens either through ProctorU remote proctoring or at a Pearson VUE test center, depending on what's authorized for your registered attempt - worth confirming early since it can affect how you plan your test-day environment and equipment checks. Scheduling logistics and key dates are covered in more depth in the GREM Exam Dates guide.
Mapping Study Time to the 73% Target
A generic study calendar won't help you clear a domain-heavy, hands-on exam like this one. Instead, structure your remaining weeks around the domains where you're weakest and where CyberLive tasks are most likely to appear.
Foundational Domains
- Core Reverse Engineering Concepts and Static Analysis Fundamentals
- Malware Analysis Fundamentals and Behavioral Analysis Fundamentals
File-Type-Specific Analysis
- Analyzing Malicious Office Macros, PDFs, and RTF Files
- Examining .NET Malware
Hands-On Heavy Domains
- Unpacking and Debugging Packed Malware - build lab reps here
- Identifying and Bypassing Anti-Analysis Techniques
- Overcoming Misdirection Techniques and Analyzing Obfuscated Malware
Integration and Practice Exam
- Common Malware Patterns, Malware Flow Control and Structures, Reversing Functions in Assembly
- Take the standalone official practice test and review every miss by domain
This sequencing isn't arbitrary - it moves from concepts you'll rely on throughout the exam toward the domains most likely to show up as time-consuming CyberLive tasks, so you build practical fluency before test day rather than cramming it in at the last minute. For a more complete walkthrough of preparation strategy, see the GREM Study Guide 2026.
Open-Book Rules and Their Effect on Score Strategy
GREM is open book, and this is one of its more distinctive features compared to many technical certifications. You're permitted hardcopy books, notes, and an index during the exam. What's prohibited is just as important: internet access, personal electronic references, and any collections of practice questions or answers.
This changes how you should prepare. Since you can bring a physical index, part of your study time should go toward building one - organized by domain, with page references to your FOR610 materials or personal notes, so you can locate a specific technique or syntax reference in seconds rather than minutes. Given the tight per-question time budget discussed earlier, a well-organized index can be the difference between finishing comfortably above 73% and running out of time on the last several questions.
Key Takeaway
Build your index before exam day, not during it. A tabbed, domain-organized reference document turns "open book" into a genuine speed advantage rather than a fallback you fumble through under pressure.
The exam engine also provides a built-in calculator and scratch notepad, which is useful for tracking offsets, byte values, or working through structure calculations during CyberLive tasks - small tools, but worth knowing about before you're mid-exam and searching for them.
If you're still assessing whether the difficulty of this open-book-but-hands-on format matches your current skill level, the How Hard Is the GREM Exam guide and the GREM Pass Rate data both offer useful context before you commit to a registration date. And if you're weighing whether the investment makes sense at all, the GREM ROI analysis covers that decision in detail - you can also review sample question formats and drills on the main practice test site before scheduling.
FAQ
GIAC requires a minimum score of 73% to pass the GIAC Reverse Engineering Malware exam, which consists of 66 questions delivered over a 3-hour proctored session.
GIAC does not publish a separate weighting for CyberLive versus multiple-choice items; both contribute to your overall score against the single 73% threshold.
You'll need to wait 30 days before retaking the exam, and the retake attempt costs $899. Reviewing which domains you missed before scheduling a retake is strongly recommended.
Yes - GREM is open book, allowing hardcopy books, notes, and an index. Internet access, personal electronic devices, and practice-question collections are not permitted.
You have 120 days from activation of your attempt to sit for and complete the exam, so plan your study timeline backward from that window.
Clearing the 73% mark on GREM comes down to treating all 15 domains as equally testable, budgeting exam time around the mix of multiple-choice and CyberLive tasks, and using the open-book allowance strategically rather than as an afterthought. For deeper context on eligibility, pricing, and career payoff, explore the GREM Requirements guide, the GREM Salary Guide, and the quick-reference GREM Cheat Sheet - and when you're ready to gauge your readiness, practice questions on the main site are a solid next step.