nerdexam
GIAC

GREM · Question #130

What would an analyst be looking for when examining the import address table (IAT) of a Windows PE file during malware analysis?

The correct answer is B. The list of DLLs and functions that the executable will use. See the full explanation below for the reasoning.

Question

What would an analyst be looking for when examining the import address table (IAT) of a Windows PE file during malware analysis?

Options

  • ADebugging information
  • BThe list of DLLs and functions that the executable will use
  • CMetadata regarding the file's original creation date
  • DThe checksum of the file for integrity verification

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    74% (29)
  • C
    5% (2)
  • D
    8% (3)

Community Discussion

No community discussion yet for this question.

Full GREM Practice