GIAC Reverse Engineering Malware GREM Prüfungsfragen mit Lösungen:
1. In malware analysis, what is the purpose of comparing the hash of a suspicious file to known malware databases?
A) To understand the network behavior of the malware
B) To determine the exact changes made to the system by the malware
C) To potentially identify the malware and its known behaviors
D) To identify the file's original author
2. Which tool can be used to monitor network traffic during behavioral analysis of a malware sample?
A) IDA Pro
B) OllyDbg
C) Wireshark
D) Procmon
3. What is the primary purpose of using a disassembler in reverse engineering malware?
A) To observe runtime behavior of the malware
B) To modify the malware's behavior
C) To translate machine code into human-readable assembly code
D) To decrypt encoded strings
4. In the context of malware analysis, what is the significance of identifying a call to the CreateProcess function with the CREATE_SUSPENDED flag?
A) It indicates the creation of a backup copy of the malware.
B) It is a standard practice for all Windows applications for better performance.
C) It signifies that the malware may be attempting process hollowing.
D) It denotes that the malware is self-replicating.
5. What behaviors in a PDF file could indicate malicious intent? (Choose two)
A) The PDF file size is extremely small.
B) The PDF contains a script that invokes external URLs.
C) The PDF contains multiple encrypted objects.
D) The PDF has many embedded images but no scripts.
Fragen und Antworten:
| 1. Frage Antwort: C | 2. Frage Antwort: C | 3. Frage Antwort: C | 4. Frage Antwort: C | 5. Frage Antwort: B,C |






897 Kundenbewertungen

