GIAC GREM 試験概要:
| 認定ベンダー: | GIAC (Global Information Assurance Certification) / SANS Institute |
|---|---|
| 試験名: | GIAC マルウェア逆コンパイル認定資格 |
| 試験番号: | GREM |
| 認定の有効期間: | 4年 |
| 受験料: | $999 USD (試験のみ) / SANS FOR610 training 付きで $7,000+ |
| 関連資格: | GIAC マルウェア逆コンパイル (GREM) |
| 出題数: | 66-75 |
| 合格点: | 73% |
| 試験形式: | 多肢選択式, CyberLive (ハンズオンラボ) |
| 試験時間: | 180 分 |
| 対応言語: | 英語 |
| サンプル問題: | GIAC GREM サンプル問題 |
| 受験方法: | ProctorU によるオンライン監督試験、または PearsonVUE 試験センターでの受験 |
| 前提条件: | 推奨: 2年以上の IT/セキュリティ経験、Windows internals、assembly language (x86/x64)、ネットワークの基礎、および scripting (Python, C/C++) の習熟 |
| 公式シラバスのURL: | https://www.giac.org/certifications/reverse-engineering-malware-grem |
GIAC GREM 試験シラバストピック:
| セクション | 目標 |
|---|---|
| アンチ解析技術とアンパッキング | - アンチ解析技術の回避 - debugger を用いた packed malware のアンパッキング - さらなる解析のための unpacked malware の修復 - アンチ解析技術の特定 |
| マルウェア解析の基礎 | - 行動解析の基礎 - マルウェアコードおよび行動解析 - メモリフォレンジックを用いたマルウェア解析 - 静的解析の基礎 |
| Windows Assembly Code の概念 | - assembly における一般的な Windows malware の特徴 - assembly における関数のリバース - x86/x64 assembly instructions の理解 - 実行フロー制御メカニズムの解析 |
| 悪意のある文書の解析 | - 悪意のある文書ファイルの解析 - 悪意のあるブラウザスクリプトの解析 - Web ベース malware の解析 |
| .NET Malware Analysis | - .NET malware analysis techniques |
| 悪意のある実行ファイルの解析 | - 複雑な実行ファイルと fileless malware - debugger を使用した動的解析 - 一般的な malware パターン - disassembler を使用した静的解析 - コードインジェクション、フッキング、およびホロウィング技法 |
GIAC Reverse Engineering Malware 認定 GREM 試験問題:
問題 #1
Which of the following are common flow control instructions used in malware? (Choose two)
A. JMP
B. XOR
C. CALL
D. POP
問題 #2
Which of the following techniques can be used to defeat code obfuscation in malware?
A. Using encryption to hide the payload
B. Analyzing encrypted traffic
C. Deobfuscating strings during runtime
D. Disassembling the obfuscated binary in IDA Pro
問題 #3
What tool is commonly used to decompile .NET binaries for analysis?
A. OllyDbg
B. dnSpy
C. IDA Pro
D. Wireshark
問題 #4
In assembly language, which instruction is commonly used for conditional execution?
A. TEST
B. LEA
C. INC
D. CMP
問題 #5
You are analyzing a malware sample and notice it uses multiple JMP instructions that lead to dead code segments, making it difficult to follow the actual execution flow. What steps should you take to overcome this misdirection technique? (Choose three)
A. Modify the binary to change the JMP instructions to NOPs.
B. Use dynamic analysis to observe the actual execution flow of the malware.
C. Trace the stack during execution to identify valid code paths.
D. Analyze each JMP instruction to determine whether it leads to valid code.
E. Patch the binary to remove unnecessary JMP instructions.
解説:
| 問題 #1 正解: A、C | 問題 #2 正解: C | 問題 #3 正解: B | 問題 #4 正解: D | 問題 #5 正解: B、C、D |














1123 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
