最新的GIAC Reverse Engineering Malware - GREM免費考試真題
問題1
You are analyzing a malware sample and notice it uses multiple JMP instructions that lead to dead code segments, making it difficult to follow the actual execution flow. What steps should you take to overcome this misdirection technique? (Choose three)
正確答案: C,D,E
問題2
What is one of the primary purposes of misdirection techniques used by malware?
正確答案: C
問題3
A sample repeatedly checks CPU vendor strings. Which goal is MOST likely?
正確答案: A
問題4
Which API calls are commonly used by malware to manipulate processes and inject code?
(Choose two)
(Choose two)
正確答案: A,C
問題5
What is the purpose of employing anti-disassembly techniques in malware?
正確答案: A
問題6
A PE file's .rsrc section contains an embedded executable. What is the MOST common malware characteristic?
正確答案: C
問題7
What would an analyst be looking for when examining the import address table (IAT) of a Windows PE file during malware analysis?
正確答案: C
問題8
When analyzing .NET malware, which of the following findings would be considered significant?
(Choose Three)
(Choose Three)
正確答案: A,C,E

