GREM Practice Questions
Prepare for GREM with more than an answer.
- Exam fee
- $999 USD
- Level
- Advanced
- Valid for
- 4 years
Domains covered on the exam 6
- Malware Analysis Fundamentals10%
- Windows Assembly Code Concepts and Reverse Engineering20%
- Analyzing Malicious Documents and Scripts18%
- In-Depth Malware Analysis and .NET Programs15%
- Self-Defending Malware and Anti-Analysis Techniques17%
- Advanced Malware Analysis Techniques20%
- 1
Case Study: You are investigating a targeted attack involving a Microsoft Word document. The document contains no VBA macros. However, when users open it, a command prompt briefly appears, and malware is installed.
Upon inspecting the document's internal XML (specifically
word/document.xml), you find a reference to an external application protocol in a field code:{ DDEAUTO c:\windows\system32\cmd.exe "/k powershell.exe -NoP -w hidden..." }What is this attack technique called?
Show answer details
Correct answer: D
DDE (Dynamic Data Exchange) is a legacy Microsoft protocol used for data transfer between applications. Attackers abuse the DDEAUTO field code in Word to execute arbitrary commands (like cmd.exe or PowerShell) without requiring macros to be enabled.
- 2
You are manually unpacking a malware sample in x64dbg. You have identified a loop that decrypts code and a
JMPinstruction that transfers control to a memory address far away from the current instruction pointer (EIP), specifically into the.textsection. This destination address is most likely the:Show answer details
Correct answer: B
In packed malware, the unpacking stub runs first to decrypt the payload. Once finished, it typically executes a 'tail jump' to the Original Entry Point (OEP) of the unpacked code to begin malicious execution. Identifying this jump is key to dumping the unpacked executable.
- 3
You open a .NET executable in
dnSpy. Instead of readable class and method names, you see unreadable characters or names likeA,b,c. The code logic is also hard to follow due to control flow flattening. Which tool would be most effective to preprocess this file before further analysis?Show answer details
Correct answer: A
de4dotis a powerful open-source .NET deobfuscator and unpacker. It can automatically detect and reverse many common .NET obfuscation techniques (like renaming, string encryption, and control flow flattening), making the code readable in decompilers like dnSpy. - 4
In a Process Hollowing attack, the malware creates a legitimate process (like
svchost.exe) in a suspended state. Which API call is typically used next to remove the original legitimate code from the suspended process's memory?Show answer details
Correct answer: B
NtUnmapViewOfSectionis the specific native API used to unmap (hollow out) the original executable image from the memory of the suspended process, clearing the way for the malware to inject its own payload. - 5
You are analyzing a .NET malware sample that seems to load another assembly dynamically at runtime from a resource. Which method in the .NET Framework is most commonly used to load this byte array as an executable assembly?
Show answer details
Correct answer: D
Assembly.Load()(orAssembly.Load(byte[])) is part of the System.Reflection namespace. Malware uses it to load a .NET assembly directly from memory (often decrypted from resources) without writing it to disk. - 6
A malware analyst is configuring a dedicated analysis lab using VMware Workstation. To ensure the malware can be analyzed dynamically while simulating Internet services without exposing the production network or the actual Internet, which network configuration is the MOST appropriate?
Show answer details
Correct answer: B
A Host-Only network isolates the VMs from the external network entirely. By placing a REMnux VM (configured with tools like INetSim or FakeNet) on the same Host-Only network and setting it as the gateway for the malware VM, the analyst can intercept and simulate all network traffic safely.
- 7
During the static analysis of a suspicious PE file named 'invoice.exe', you observe that the 'Virtual Size' of the
.textsection is 0x40000 bytes, while the 'Size of Raw Data' is 0 bytes. What is the most likely explanation for this anomaly?Show answer details
Correct answer: C
A high Virtual Size combined with a Raw Data size of 0 in the executable code section (.text) typically indicates that the malware is packed. The packer allocates memory space during loading but does not store the code on disk in that section; instead, a stub unpacks the code into that memory region during execution.
- 8
While monitoring a malware sample with Process Monitor (ProcMon), you notice a repetitive operation where the process queries the registry key
HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Immediately after, it creates a file namedupdate.exein%APPDATA%. Which phase of the malware lifecycle are you observing?Show answer details
Correct answer: D
The
Runregistry key is a classic location for establishing persistence, ensuring the malware starts automatically upon user login. Writing an executable to AppData and referencing it in the Run key confirms the installation of a persistence mechanism. - 9
You are analyzing a 32-bit assembly snippet in x64dbg. You encounter the following instructions:
PUSH EBP MOV EBP, ESP SUB ESP, 10 MOV [EBP-4], 0What is the purpose of the instruction
SUB ESP, 10in this function prologue?Show answer details
Correct answer: D
In the standard x86 function prologue, subtracting from ESP grows the stack downwards, reserving space for the function's local variables. Here, 0x10 bytes are allocated.
- 10
Examine the following x86 assembly block found in a malware sample:
MOV ECX, 100 XOR EAX, EAX LABEL_START: ADD EAX, [EBX + ECX * 4] DEC ECX JNZ LABEL_STARTWhich high-level programming construct does this assembly block represent?
Show answer details
Correct answer: C
The code initializes a counter (ECX), performs an operation, decrements the counter, and jumps back if the counter is not zero (JNZ). Since the check happens at the end, it functions as a do-while loop structure iterating until ECX reaches 0.
