GIAC GREM Certification Sample Questions

GREM Dumps, GREM PDF, GREM VCE, GIAC Reverse Engineering Malware VCE, GIAC GREM PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Reverse Engineering Malware (GREM) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GREM certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GREM Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Reverse Engineering Malware (GREM) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Reverse Engineering Malware exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GREM Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GREM Sample Questions:

01. In a dumped image, API calls appear as call dword ptr [0x00A2100C], and 0x00A2100C lies in a region the stub allocated at run time rather than in any section described by the dump's import directory. The dump's import directory is empty.
What accounts for this, and what does an import reconstructor such as Scylla do about it?
a) The stub resolved each API itself and stored the resulting addresses in a table of its own, so the dump has no directory describing them; the reconstructor reads those stored pointers, maps each back to the module and export it belongs to, and writes a fresh import directory and thunk table into the image.
b) The dump's import directory was captured intact but its entries hold raw file offsets rather than relative virtual addresses, so the reconstructor converts each entry and rewrites the directory in place.
c) The addresses are forwarded exports that Windows resolves only at first call, so the reconstructor forces each one to resolve and then freezes the resulting address into the image.
d) The stub encrypted the imported function names to defeat static analysis, so the reconstructor decrypts the name strings and restores the original hint and name table.
 
02. You dump a sample after its stub's tail transfer and rebuild the imports. The dump loads in a disassembler, but the function at the entry point you set has no prologue: its first instruction references ebp as though a frame had already been established, and the local offsets it uses are consistent with a frame that nothing in the dump creates. Everything further into the code section disassembles cleanly.
What best explains what you are looking at?
a) The import reconstruction wrote its rebuilt thunk table over the start of the code section, so the original prologue was destroyed after the dump was taken.
b) The packer moved the entry point's opening instructions into its own stub and ran them there, so those bytes were never written into the image and the dump begins part-way into the function.
c) The section alignment was repaired with the file alignment rather than the virtual alignment, so every address in the dump is shifted and the entry point now resolves into the middle of the preceding function.
d) The dump was taken before the final decompression pass, so the entry point's bytes are still compressed and decode as unrelated instructions.
 
03. The decompiled sample reads an embedded resource out of its own assembly, passes the bytes through a routine that decrypts them against a key it derives at run time, and hands the result to Assembly.Load as a byte array. Extracted with a resource editor, the resource itself is high-entropy, carries no recognizable header and yields no strings.
Which step puts the second assembly in front of your decompiler?
a) Search the sample's directory for a second file after the run, since loading from a byte array is a wrapper around a temporary file the runtime writes out.
b) Open the resource directly in the decompiler, since the runtime stores an embedded assembly in a resource in the form the load call expects.
c) Break on the Assembly.Load call in a managed debugger, write the byte-array argument out to a file, and decompile that file.
d) Patch the decryption routine to return its input unchanged, so the resource is rewritten in clear text on the next run.
 
04. While tracing a sample you find a JZ whose target address the disassembler does not show as the start of any instruction — it falls in the middle of a four-byte MOV that the listing renders as a single line. You set a breakpoint on the branch, let it be taken, and single-step from the target. The processor executes two short, valid instructions from that address and the function goes on to behave consistently.
What is this construct, and what does it mean for the static listing?
a) The processor realigns to the next whole instruction boundary when a branch lands inside an instruction, so the two instructions executed are the tail of the MOV and the listing is accurate as shown.
b) The bytes encode two different valid instruction streams depending on the offset decoding begins at, and the disassembler can render only one of them at a time, so the instructions the taken branch actually executes are present in the file but absent from the listing.
c) The disassembler misclassified a data item as a MOV; the address is the base of a jump table and the branch indexes into its entries.
d) The jump target is self-modifying code: the MOV is rewritten before the branch is taken, so the bytes present at that address at run time differ from the bytes the file holds at that offset.
 
05. Inside a loop body you find two unconditional jumps. One targets the instruction immediately after the loop's backward conditional jump. The other targets the increment that sits just before that backward jump.
Which two statements correctly identify the source constructs these jumps came from?
(Choose two.)
a) Both jumps are tail duplication of the loop condition by the optimizer and correspond to no break or continue in the source.
b) The jump past the backward conditional jump is a break, since it leaves the loop without re-testing the condition.
c) The jump past the backward conditional jump is a goto out of the function, because a break compiles to the loop's own back edge.
d) The jump to the increment is a break, since leaving the loop requires the induction variable to be advanced one final time.
e) The jump to the increment is a continue, skipping the rest of the body while keeping the loop running.
 
06. Two RTF samples arrive from the same campaign. The first declares an object whose class is a link handler; opening the document causes an outbound fetch of a remote file, which the script host then executes. The second declares an object whose class names a legacy equation component; its \objdata ends in a long run of bytes that resolves to shellcode, nothing is fetched, and the payload executes inside the equation component's own process.
What distinguishes the second sample's mechanism from the first's?
a) The second requires the user to enable editing before it runs whereas the first runs automatically, and both are logic flaws in object handling with no memory corruption involved in either.
b) The second delivers its payload as macro code that the equation component hosts, carried compressed in the object data, so the two differ only in whether the code arrives inline or over the network.
c) The second corrupts memory inside a legacy component that parses the object's data into a fixed-size buffer and so takes control in that component's process, while the first abuses a flaw in how a linked object is fetched and handed onward and corrupts nothing.
d) Both abuse the same linked-object flaw, and the second merely resolves its link to a path already present on the host, which is why no traffic is seen and why the run of bytes is a decoy.
 
07. You clear the BeingDebugged byte in a sample's PEB, and IsDebuggerPresent now returns zero for it. The sample still terminates, immediately after a call to NtQueryInformationProcess requesting ProcessDebugPort.
Why does the edit you made not affect this second check?
a) The query returns the same PEB value through a different path, so the byte must also be cleared in the process parameters block that this path reads.
b) The function's address is bound in ntdll at load time, so the result was captured before your edit and a freshly started process would report correctly.
c) The query reports the debug registers of the calling thread, so the answer changes only once the hardware breakpoints are cleared from that thread's context as well.
d) The kernel answers it from the debug object attached to the process, not from any field the process can edit.
 
08. A stub calls VirtualAlloc with PAGE_EXECUTE_READWRITE, then runs a copy loop that fills the returned region. You want the debugger to halt at the transfer of control into that region, without stepping the loop.
Which two approaches halt execution at that transfer?
(Choose two.)
a) Set a breakpoint on VirtualFree, so the debugger halts once the stub releases the region it executed from.
b) Set a write breakpoint on the allocated region, so the debugger halts on the first write the copy loop performs.
c) Set a memory breakpoint for execution over the whole allocated region, so the first instruction fetched from any page in it halts the debugger because the fetch itself is the access being watched.
d) Set a software breakpoint at the region's base address before the copy loop runs, so the patched 0xCC halts execution when the code is reached.
e) Set a breakpoint on the stub's indirect call or jmp whose operand register holds the allocation's address, so the debugger halts on the instruction that performs the transfer.
 
09. You load a sample in a debugger configured to break at the image entry point. When the break occurs, a mutex the sample creates already exists and a flag in its data section is already set, although no instruction you can reach has executed. The file has a populated TLS directory.
What happened, and what setting prevents it?
a) Its TLS callbacks ran ahead of the entry point; the debugger has to be set to break on the TLS callback, or at the system breakpoint, so that the callback can be examined before it executes.
b) The loader mapped the thread-local storage section as executable and treated its first bytes as the image's real entry point; correcting AddressOfEntryPoint to point into the code section instead makes the debugger stop before any of it runs.
c) A forwarded export resolved by the loader executed the code; breaking on LoadLibraryA before the entry point catches it.
d) An imported library ran the code from its own initialization routine; excluding that module from the debugger's load list stops it running.
 
10. A sample creates a worker thread whose first act is a call to NtSetInformationThread on itself with ThreadHideFromDebugger. It never reads a result back and never branches on one. Your debugger, attached from the start, then stops seeing that thread: breakpoints inside it no longer halt, and the process dies at the first exception the thread raises.
Which two statements about this technique are correct?
(Choose two.)
a) The setting applies to the whole process, so one call at startup covers every thread the sample creates afterwards.
b) It asks nothing about whether a debugger is present, so no result is read; countering it means stopping the call taking effect rather than falsifying an answer.
c) It suppresses delivery of that thread's debug events, so breakpoints and exceptions raised in it stop reaching whatever is attached.
d) It detaches the debugger from the process, which is why tracing can resume only by attaching to a fresh run.
e) The call fails with an error while a debugger is attached, and the sample treats that failure as its detection signal, which is why it makes the call so early.

Answers:

Question: 01
Answer: a
Question: 02
Answer: b
Question: 03
Answer: c
Question: 04
Answer: b
Question: 05
Answer: b, e
Question: 06
Answer: c
Question: 07
Answer: d
Question: 08
Answer: c, e
Question: 09
Answer: a
Question: 10
Answer: b, c

Note: For any error in GIAC Reverse Engineering Malware (GREM) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (79 votes)