GIAC Reverse Engineering Malware Exam Prep
Free practice questions

Free GREM Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GREM exam has 66 questions and runs 3 hours.

These 10 free GREM questions are organized by exam domain, so you can see how each part of the GIAC Reverse Engineering Malware blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Analyzing Malicious Office Macros

Question 1

An emailed .docm contains a valid VBA project. Source extraction shows an empty Document_Open procedure, but disassembled p-code for that procedure contains command-string construction followed by WScript.Shell.Run. Nothing has been executed in Word. To recover the command the document is capable of launching, the analyst should:

Show answer & explanation

Correct answer: D - Reconstruct the compiled macro's strings and arguments at the Run call.

Domain 2: Analyzing Malicious PDFs

Question 2

The current catalog of a PDF contains /OpenAction 17 0 R. The referenced object is: 17 0 obj << /S /JavaScript /J#53 26 0 R >> endobj Object 26 is a stream with /Filter [/ASCIIHexDecode /FlateDecode]. A keyword scanner reports no literal /JS token. What is the valid route to the script requested at document open?

Show answer & explanation

Correct answer: A - Extract object 26; ASCII-hex decode it, then decompress the result.

Domain 5: Behavioral Analysis Fundamentals

Question 3

An analyst's Process Monitor view is filtered to PID 4120. It shows that process starting PID 5084 and exiting two seconds later. Packet capture then records repeated connections from the analysis VM, but the filtered view contains no later activity. The team is about to report that the sample stopped after launch. What missing observation would most directly test that conclusion?

Show answer & explanation

Correct answer: C - Process Monitor events for PID 5084 and its descendants, matched to process lifetimes.

Domain 6: Common Malware Patterns

Question 4

A launcher creates notepad.exe with CREATE_SUSPENDED. Before the child's primary thread runs, the launcher unmaps its executable image, places a different PE image in that address space, changes the primary thread's execution context, and resumes it. No additional thread is created in the child. Which technique explains the replacement code executing under the child's process name?

Show answer & explanation

Correct answer: B - Process hollowing of a suspended child.

Domain 7: Core Reverse Engineering Concepts

Question 5

This x64 call site is being examined to recover a configuration string: lea rcx, [rbx+0x30] call ExamineString ExamineString accepts one pointer to a NUL-terminated UTF-16LE string. The eight bytes at RBX+0x30 are 63 00 66 00 67 00 00 00. What does the callee receive in RCX?

Show answer & explanation

Correct answer: D - A pointer to the three-character UTF-16LE string cfg.

Domain 8: Examining .NET Malware

Question 6

Filesystem monitoring of a .NET loader records no second-stage file. A managed debugger shows an embedded resource being decoded into byte[] payload; the next statement is Assembly.Load(payload), followed later by a reflected method invocation. The goal is to recover the second-stage assembly without running its methods. Where is the most useful capture point?

Show answer & explanation

Correct answer: A - Capture the decoded payload byte array immediately before Assembly.Load.

Domain 10: Malware Analysis Fundamentals

Question 7

While a suspected worm is running, packet capture confirms connection attempts from a bridged analysis VM to production addresses. The hypervisor allows the VM's virtual NIC to be disconnected immediately without stopping the VM. What should the analyst do first?

Show answer & explanation

Correct answer: B - Disconnect the virtual NIC, keeping the VM running for volatile-evidence capture.

Domain 11: Malware Flow Control and Structures

Question 8

A 32-bit length routine returns EAX=0xFFFFFFFF. The caller immediately executes: cmp eax, 0x400 ja reject mov ecx, eax call consume Where does execution go, and why?

Show answer & explanation

Correct answer: D - To reject, because JA treats 0xFFFFFFFF as unsigned and greater than 0x400.

Domain 13: Reversing Functions in Assembly

Question 9

A debugger stops at the first instruction of a function using the Microsoft x64 calling convention, before its prologue changes RSP. Its recovered signature is: BOOL Decode(const BYTE *src, SIZE_T srcLen, BYTE *dst, SIZE_T dstCapacity, SIZE_T *bytesWritten); The analyst will preserve the relevant entry-time addresses and inspect the output after a successful return. Which pair identifies the destination buffer and the location that will contain its actual output length?

Show answer & explanation

Correct answer: C - Buffer: R8; length: the SIZE_T written through the entry-time pointer at [RSP+0x28].

Domain 14: Static Analysis Fundamentals

Question 10

Static triage measures a PE's .text section at 5.8 bits per byte and its .rsrc section at 7.96 bits per byte. The high-entropy resource extracts successfully as a valid compressed image. No execution trace has been collected. Which assessment best fits these measurements and the extraction result?

Show answer & explanation

Correct answer: A - The compressed image can account for the entropy without establishing executable packing.

The rest of the GREM blueprint

The GREM exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more GREM questions with explanations.

Continue in the free practice test →

View plans