Free GREM sample questions
Real questions from the GIAC Reverse Engineering Malware practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
During the static analysis of a suspicious PE file named 'invoice.exe', you observe that the 'Virtual Size' of the `.text` section is 0x40000 bytes, while the 'Size of Raw Data' is 0 bytes. What is the most likely explanation for this anomaly?
While monitoring a malware sample with Process Monitor (ProcMon), you notice a repetitive operation where the process queries the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. Immediately after, it creates a file named `update.exe` in `%APPDATA%`. Which phase of the malware lifecycle are you observing?
You are analyzing a 32-bit assembly snippet in x64dbg. You encounter the following instructions: ```assembly PUSH EBP MOV EBP, ESP SUB ESP, 10 MOV [EBP-4], 0 ``` What is the purpose of the instruction `SUB ESP, 10` in this function prologue?
Examine the following x86 assembly block found in a malware sample: ```assembly MOV ECX, 100 XOR EAX, EAX LABEL_START: ADD EAX, [EBX + ECX * 4] DEC ECX JNZ LABEL_START ``` Which high-level programming construct does this assembly block represent?
You are analyzing a function call in a 32-bit Windows malware sample. You see the following instructions: ```assembly PUSH 0 PUSH 0 PUSH 0 PUSH 0 PUSH OFFSET Command PUSH 0 CALL Kernel32.CreateProcessA ``` If the malware were compiled for a 64-bit Windows environment, how would the first four parameters be passed to `CreateProcessA` according to the Microsoft x64 calling convention?
You encounter a routine that iterates through a byte array, performing an XOR operation on each byte with the key 0x5A. What is the primary purpose of this routine in the context of malware analysis?
In x86 assembly, the `TEST` instruction is frequently used before a conditional jump. If you see `TEST EAX, EAX` followed by `JZ (Jump if Zero)`, what is the code checking?
Which of the following assembly instructions is commonly used in shellcode to calculate the current instruction pointer (EIP) location dynamically, often referred to as 'get_pc' or 'get_eip' technique?
You are reverse engineering a downloader that uses `URLDownloadToFileW`. The second parameter is the URL. In the disassembly, you see `PUSH EAX` before the call, where EAX points to a wide string. What character encoding must this string use?
10 more free samples are waiting
Create a free account to unlock the whole GREM sample bank, or get full access to all 130 practice questions in the simulator.