GIAC Reverse Engineering Malware 認定 GREM 試験問題:
1. What is the significance of analyzing the macro's trigger mechanism in a Microsoft Office document?
A) It reveals how and when the macro will execute within the document.
B) It indicates the document's compatibility with different Office versions.
C) It identifies the interaction with external applications.
D) It determines how the macro is shared across networks.
2. You are analyzing a malware sample and notice it uses multiple JMP instructions that lead to dead code segments, making it difficult to follow the actual execution flow. What steps should you take to overcome this misdirection technique? (Choose three)
A) Modify the binary to change the JMP instructions to NOPs.
B) Use dynamic analysis to observe the actual execution flow of the malware.
C) Trace the stack during execution to identify valid code paths.
D) Analyze each JMP instruction to determine whether it leads to valid code.
E) Patch the binary to remove unnecessary JMP instructions.
3. You are analyzing a suspicious Office document received as an email attachment. Upon opening, you notice the document attempts to run a macro that accesses external servers and makes changes to the registry.
Which of the following actions should be taken to confirm the malicious intent of the macro?
(Choose three)
A) Check if the macro is digitally signed by a trusted authority.
B) Verify if the document contains unusual formatting commands.
C) Decompile the macro and search for obfuscated code.
D) Investigate network traffic for outgoing connections made by the macro.
E) Disable macros and examine the document in a sandbox.
4. What is the most effective method for analyzing obfuscated malware that uses dynamic code generation?
A) Disassembling the code in IDA Pro
B) Unpacking the binary
C) Running the malware in a sandbox to observe its behavior
D) Static analysis of the binary
5. Why might malware use indirect jumps and calls as part of its execution flow?
A) To enhance the readability of the code for maintenance purposes
B) To make decompilation and debugging more difficult by obscuring the control flow
C) To improve the efficiency of execution on multi-core processors
D) To reduce the overall size of the compiled binary
質問と回答:
| 質問 # 1 正解: A | 質問 # 2 正解: B、C、D | 質問 # 3 正解: C、D、E | 質問 # 4 正解: C | 質問 # 5 正解: B |














1090 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
