GIAC Reverse Engineering Malware 試験
最新更新時間: 2026/09/21
【秋学習応援セール|10月限定キャンペーン】:GREM 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。
実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。
さらに試験準備時間の35%を節約するには、GREM 問題集を使用してください。
Question No : 1
What is the purpose of employing anti-disassembly techniques in malware?
正解:
Question No : 2
Which of the following indicators suggest the presence of .NET malware in a system? (Choose two)
正解:
Question No : 3
Which assembly instruction is commonly used to alter the flow of execution in malware?
正解:
Question No : 4
In reverse engineering .NET malware, what does dynamic analysis allow you to observe?
正解:
Question No : 5
Which API calls are commonly used by malware to manipulate processes and inject code? (Choose two)
正解:
Question No : 6
Which of the following is a common obfuscation technique used in .NET malware?
正解:
Question No : 7
Which of the following are common flow control instructions used in malware? (Choose two)
正解:
Question No : 8
You are analyzing a malware sample that appears to inject malicious code into the explorer.exe process. During execution, the malware creates a remote thread in explorer.exe and uses API calls to manipulate its memory.
How would you proceed with the analysis? (Choose three)
正解:
Question No : 9
What is the primary objective of conducting a static analysis on a suspected malware file?
正解:
Question No : 10
When using a debugger on .NET malware, what would be a primary reason to set a breakpoint at a specific method?
正解:
Question No : 11
When analyzing a Windows executable, which of the following indicators most strongly suggests that the file is packed?
正解:
Question No : 12
What is a key indicator that JavaScript code has been obfuscated?
正解:
Question No : 13
API hooking implemented by malware is primarily used for which purpose?
正解:
Question No : 14
What is the primary reason attackers pack malware binaries?
正解:
Question No : 15
What is a common indicator that a function in assembly language is about to return a value?
正解: