GIAC GREM Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Analyse von .NET-Schadsoftware | - Verfahren zur Analyse von .NET-Schadsoftware |
| Grundlagen des Windows-Assembler-Codes | - Analyse von Ablaufsteuerungsmechanismen - Typische Merkmale von Windows-Schadsoftware im Assembler-Code - Rückentwicklung von Funktionen im Assembler-Code - Verstehen von x86/x64-Assemblerbefehlen |
| Grundlagen der Analyse von Schadsoftware | - Analyse von Schadsoftware mithilfe von Speicherforensik - Code- und verhaltensbasierte Analyse von Schadsoftware - Grundlagen der verhaltensbasierten Analyse - Grundlagen der statischen Analyse |
| Analyse bösartiger Dokumente | - Analyse bösartiger Skripte in Browsern - Analyse bösartiger Dokumentdateien - Analyse webbasierter Schadsoftware |
| Techniken zur Analysevermeidung und Entpackung | - Erkennung von Techniken zur Analysevermeidung - Umgehung von Techniken zur Analysevermeidung - Entpackung gepackter Schadsoftware mithilfe eines Debuggers - Wiederherstellung entpackter Schadsoftware für weitergehende Analysen |
| Analyse bösartiger ausführbarer Dateien | - Komplexe ausführbare Dateien und dateilose Schadsoftware - Statische Analyse mithilfe von Disassemblern - Techniken zur Code-Injektion, zum Hooking und zur Prozess-Hollowing - Dynamische Analyse mithilfe von Debuggern - Typische Muster von Schadsoftware |
GIAC Reverse Engineering Malware GREM Prüfungsfragen mit Lösungen
In malware analysis, what is the purpose of comparing the hash of a suspicious file to known malware databases?
- A. To understand the network behavior of the malware
- B. To determine the exact changes made to the system by the malware
- C. To potentially identify the malware and its known behaviors
- D. To identify the file's original author
Antwort: C 🗳️
Which tool can be used to monitor network traffic during behavioral analysis of a malware sample?
- A. IDA Pro
- B. OllyDbg
- C. Wireshark
- D. Procmon
Antwort: C 🗳️
What is the primary purpose of using a disassembler in reverse engineering malware?
- A. To observe runtime behavior of the malware
- B. To modify the malware's behavior
- C. To translate machine code into human-readable assembly code
- D. To decrypt encoded strings
Antwort: C 🗳️
In the context of malware analysis, what is the significance of identifying a call to the CreateProcess function with the CREATE_SUSPENDED flag?
- A. It indicates the creation of a backup copy of the malware.
- B. It is a standard practice for all Windows applications for better performance.
- C. It signifies that the malware may be attempting process hollowing.
- D. It denotes that the malware is self-replicating.
Antwort: C 🗳️
What behaviors in a PDF file could indicate malicious intent? (Choose two)
- A. The PDF file size is extremely small.
- B. The PDF contains a script that invokes external URLs.
- C. The PDF contains multiple encrypted objects.
- D. The PDF has many embedded images but no scripts.
Antwort: B,C 🗳️






1118 Kundenbewertungen

