GIAC Reverse Engineering Malware Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 130 questions. Use the simulator for timed and flashcard mode.

Try Simulator

GREM Sample Questions

  1. Question 1

    Q1

    A malware analyst is configuring a dedicated analysis lab using VMware Workstation. To ensure the malware can be analyzed dynamically while simulating Internet services without exposing the production network or the actual Internet, which network configuration is the MOST appropriate?

    Show answer & explanation

    Correct answer: C

    A Host-Only network isolates the VMs from the external network entirely. By placing a REMnux VM (configured with tools like INetSim or FakeNet) on the same Host-Only network and setting it as the gateway for the malware VM, the analyst can intercept and simulate all network traffic safely.

  2. Question 2

    Q2

    During the static analysis of a suspicious PE file named 'invoice.exe', you observe that the 'Virtual Size' of the .text section is 0x40000 bytes, while the 'Size of Raw Data' is 0 bytes. What is the most likely explanation for this anomaly?

    Show answer & explanation

    Correct answer: B

    A high Virtual Size combined with a Raw Data size of 0 in the executable code section (.text) typically indicates that the malware is packed. The packer allocates memory space during loading but does not store the code on disk in that section; instead, a stub unpacks the code into that memory region during execution.

  3. Question 3

    Q3

    While monitoring a malware sample with Process Monitor (ProcMon), you notice a repetitive operation where the process queries the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Immediately after, it creates a file named update.exe in %APPDATA%. Which phase of the malware lifecycle are you observing?

    Show answer & explanation

    Correct answer: B

    The Run registry key is a classic location for establishing persistence, ensuring the malware starts automatically upon user login. Writing an executable to AppData and referencing it in the Run key confirms the installation of a persistence mechanism.

  4. Question 4

    Q4

    You are analyzing a 32-bit assembly snippet in x64dbg. You encounter the following instructions:

    PUSH EBP
    MOV EBP, ESP
    SUB ESP, 10
    MOV [EBP-4], 0
    

    What is the purpose of the instruction SUB ESP, 10 in this function prologue?

    Show answer & explanation

    Correct answer: A

    In the standard x86 function prologue, subtracting from ESP grows the stack downwards, reserving space for the function's local variables. Here, 0x10 bytes are allocated.

  5. Question 5

    Q5

    Examine the following x86 assembly block found in a malware sample:

    MOV ECX, 100
    XOR EAX, EAX
    LABEL_START:
    ADD EAX, [EBX + ECX * 4]
    DEC ECX
    JNZ LABEL_START
    

    Which high-level programming construct does this assembly block represent?

    Show answer & explanation

    Correct answer: B

    The code initializes a counter (ECX), performs an operation, decrements the counter, and jumps back if the counter is not zero (JNZ). Since the check happens at the end, it functions as a do-while loop structure iterating until ECX reaches 0.

  6. Question 6

    Q6

    You are analyzing a function call in a 32-bit Windows malware sample. You see the following instructions:

    PUSH 0
    PUSH 0
    PUSH 0
    PUSH 0
    PUSH OFFSET Command
    PUSH 0
    CALL Kernel32.CreateProcessA
    

    If the malware were compiled for a 64-bit Windows environment, how would the first four parameters be passed to CreateProcessA according to the Microsoft x64 calling convention?

    Show answer & explanation

    Correct answer: B

    The Microsoft x64 calling convention (fastcall) requires the first four integer or pointer arguments to be passed in registers RCX, RDX, R8, and R9 respectively. Any additional arguments are pushed onto the stack.

  7. Question 7

    Q7

    You encounter a routine that iterates through a byte array, performing an XOR operation on each byte with the key 0x5A. What is the primary purpose of this routine in the context of malware analysis?

    Show answer & explanation

    Correct answer: C

    Single-byte XOR encoding is a very common and simple obfuscation technique used by malware to hide strings (like C2 URLs) and payloads from static string analysis tools.

  8. Question 8

    Q8

    In x86 assembly, the TEST instruction is frequently used before a conditional jump. If you see TEST EAX, EAX followed by JZ (Jump if Zero), what is the code checking?

    Show answer & explanation

    Correct answer: B

    TEST EAX, EAX performs a bitwise AND operation but discards the result, only setting flags. If EAX is zero, the Zero Flag (ZF) is set to 1. The JZ instruction then jumps if ZF is 1. Essentially, it checks if the register is empty/null/zero.

  9. Question 9

    Q9

    Which of the following assembly instructions is commonly used in shellcode to calculate the current instruction pointer (EIP) location dynamically, often referred to as 'get_pc' or 'get_eip' technique?

    Show answer & explanation

    Correct answer: B

    Since EIP cannot be accessed directly in x86 (e.g., MOV EAX, EIP is invalid), shellcode often uses a CALL to the next instruction (or a near offset). The CALL pushes the return address (the current IP) onto the stack. The subsequent POP instruction then retrieves that address into a register.

  10. Question 10

    Q10

    You are reverse engineering a downloader that uses URLDownloadToFileW. The second parameter is the URL. In the disassembly, you see PUSH EAX before the call, where EAX points to a wide string. What character encoding must this string use?

    Show answer & explanation

    Correct answer: B

    Windows API functions ending in 'W' (e.g., URLDownloadToFileW) expect Wide strings, which in Windows are encoded as UTF-16 Little Endian (2 bytes per character). Functions ending in 'A' expect ASCII/ANSI strings.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the GREM sample set.

Lifetime One

Own this practice test forever.

$
$79.99
one-time
  • Full access to 130 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon