Reverse Engineering

← all quizzes

Answer all 15 questions, then submit. You need 75% to pass. If you don't pass, the reattempt unlocks after 24 hours.

Q1. `ltrace` reveals a program's:
Q2. Ghidra and IDA are principally used to:
Q3. Malware that checks CPU count, uptime and MAC prefixes is performing:
Q4. A very high entropy section in a PE file usually suggests:
Q5. The file command identifies a binary primarily by:
Q6. Fileless malware is so named because it primarily:
Q7. A key safety measure for dynamic malware analysis is:
Q8. ltrace differs from strace in that ltrace traces:
Q9. The NX / DEP protection prevents:
Q10. The strings utility is useful early because it can reveal:
Q11. Static analysis means examining malware:
Q12. A rootkit is characterised by its goal of:
Q13. A worm differs from a virus because a worm:
Q14. A YARA rule is used to:
Q15. Setting a breakpoint in a debugger lets an analyst: