最新的GIAC Reverse Engineering Malware - GREM免費考試真題
A sample uses heavy obfuscation and multiple layers of unpacking. Which approach is MOST effective?
正確答案: D
In the context of malware analysis, what is the significance of identifying a call to the CreateProcess function with the CREATE_SUSPENDED flag?
正確答案: D
Which of the following tools is commonly used for basic static analysis of malware?
正確答案: B
What is a key indicator that JavaScript code has been obfuscated?
正確答案: B
Which technique can be utilized to hide malicious macro code within an Office document?
正確答案: D
A PE file's .rsrc section contains an embedded executable. What is the MOST common malware characteristic?
正確答案: D
What is the primary reason attackers pack malware binaries?
正確答案: C
What is the primary advantage of .NET malware for attackers?
正確答案: B