Malware & Forensics interview questions

54 Malware & Forensics questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Virus?

Junior
  1. A.malware that mutates its code on each infection to evade signature detection
  2. B.executing suspect files in an isolated environment to observe their behavior safely
  3. C.analyzing RAM captures to find running malware, injected code, and artifacts
  4. D.malware that attaches to a host file and spreads when that file is executed

Answer + AI explanation with Pro

2. Which term means: "malware that attaches to a host file and spreads when that file is executed"?

Junior
  1. A.Virus
  2. B.Worm
  3. C.Rootkit
  4. D.Timeline analysis

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Virus — self-replicating malware that spreads across networks without user interaction
  2. B.Virus — malware that attaches to a host file and spreads when that file is executed
  3. C.Virus — executing suspect files in an isolated environment to observe their behavior safely
  4. D.Virus — malware disguised as legitimate software to trick users into running it

Answer + AI explanation with Pro

4. What is Worm?

Junior
  1. A.self-replicating malware that spreads across networks without user interaction
  2. B.pattern-matching rules that identify and classify malware by textual or binary signatures
  3. C.analyzing RAM captures to find running malware, injected code, and artifacts
  4. D.stealthy malware that hides its presence and grants persistent privileged access

Answer + AI explanation with Pro

5. Which term means: "self-replicating malware that spreads across networks without user interaction"?

Junior
  1. A.Worm
  2. B.Polymorphic malware
  3. C.Rootkit
  4. D.Sandboxing

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Worm — malicious code that runs in memory using legitimate tools, leaving little on disk
  2. B.Worm — pattern-matching rules that identify and classify malware by textual or binary signatures
  3. C.Worm — executing suspect files in an isolated environment to observe their behavior safely
  4. D.Worm — self-replicating malware that spreads across networks without user interaction

Answer + AI explanation with Pro

7. What is Trojan?

Junior
  1. A.malicious code that runs in memory using legitimate tools, leaving little on disk
  2. B.malware disguised as legitimate software to trick users into running it
  3. C.analyzing RAM captures to find running malware, injected code, and artifacts
  4. D.malware or device that records keystrokes to capture credentials and data

Answer + AI explanation with Pro

8. Which term means: "malware disguised as legitimate software to trick users into running it"?

Junior
  1. A.YARA rules
  2. B.Polymorphic malware
  3. C.Trojan
  4. D.Worm

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Trojan — malicious code that runs in memory using legitimate tools, leaving little on disk
  2. B.Trojan — executing suspect files in an isolated environment to observe their behavior safely
  3. C.Trojan — malware disguised as legitimate software to trick users into running it
  4. D.Trojan — malware or device that records keystrokes to capture credentials and data

Answer + AI explanation with Pro

10. What is Rootkit?

Junior
  1. A.executing suspect files in an isolated environment to observe their behavior safely
  2. B.self-replicating malware that spreads across networks without user interaction
  3. C.stealthy malware that hides its presence and grants persistent privileged access
  4. D.malware that attaches to a host file and spreads when that file is executed

Answer + AI explanation with Pro

11. Which term means: "stealthy malware that hides its presence and grants persistent privileged access"?

Junior
  1. A.Sandboxing
  2. B.Polymorphic malware
  3. C.Keylogger
  4. D.Rootkit

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Rootkit — stealthy malware that hides its presence and grants persistent privileged access
  2. B.Rootkit — self-replicating malware that spreads across networks without user interaction
  3. C.Rootkit — analyzing RAM captures to find running malware, injected code, and artifacts
  4. D.Rootkit — executing suspect files in an isolated environment to observe their behavior safely

Answer + AI explanation with Pro

13. What is Keylogger?

Mid
  1. A.malware disguised as legitimate software to trick users into running it
  2. B.malware or device that records keystrokes to capture credentials and data
  3. C.malicious code that runs in memory using legitimate tools, leaving little on disk
  4. D.pattern-matching rules that identify and classify malware by textual or binary signatures

Answer + AI explanation with Pro

14. Which term means: "malware or device that records keystrokes to capture credentials and data"?

Mid
  1. A.YARA rules
  2. B.Memory forensics
  3. C.Keylogger
  4. D.Fileless malware

Answer + AI explanation with Pro

15. Which statement is correct?

Mid
  1. A.Keylogger — malware that attaches to a host file and spreads when that file is executed
  2. B.Keylogger — malware or device that records keystrokes to capture credentials and data
  3. C.Keylogger — executing suspect files in an isolated environment to observe their behavior safely
  4. D.Keylogger — pattern-matching rules that identify and classify malware by textual or binary signatures

Answer + AI explanation with Pro

16. What is Fileless malware?

Mid
  1. A.reconstructing the sequence of events from filesystem and log timestamps during an investigation
  2. B.pattern-matching rules that identify and classify malware by textual or binary signatures
  3. C.malware that mutates its code on each infection to evade signature detection
  4. D.malicious code that runs in memory using legitimate tools, leaving little on disk

Answer + AI explanation with Pro

17. Which term means: "malicious code that runs in memory using legitimate tools, leaving little on disk"?

Mid
  1. A.Keylogger
  2. B.Disk imaging
  3. C.Fileless malware
  4. D.Worm

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.Fileless malware — malware that attaches to a host file and spreads when that file is executed
  2. B.Fileless malware — malicious code that runs in memory using legitimate tools, leaving little on disk
  3. C.Fileless malware — creating a bit-for-bit forensic copy of storage to preserve evidence integrity
  4. D.Fileless malware — malware or device that records keystrokes to capture credentials and data

Answer + AI explanation with Pro

19. What is Memory forensics?

Mid
  1. A.malware that mutates its code on each infection to evade signature detection
  2. B.malware that attaches to a host file and spreads when that file is executed
  3. C.analyzing RAM captures to find running malware, injected code, and artifacts
  4. D.creating a bit-for-bit forensic copy of storage to preserve evidence integrity

Answer + AI explanation with Pro

20. Which term means: "analyzing RAM captures to find running malware, injected code, and artifacts"?

Mid
  1. A.Disk imaging
  2. B.YARA rules
  3. C.Polymorphic malware
  4. D.Memory forensics

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Memory forensics — analyzing RAM captures to find running malware, injected code, and artifacts
  2. B.Memory forensics — malware that mutates its code on each infection to evade signature detection
  3. C.Memory forensics — stealthy malware that hides its presence and grants persistent privileged access
  4. D.Memory forensics — executing suspect files in an isolated environment to observe their behavior safely

Answer + AI explanation with Pro

22. What is Sandboxing?

Mid
  1. A.reconstructing the sequence of events from filesystem and log timestamps during an investigation
  2. B.malware disguised as legitimate software to trick users into running it
  3. C.executing suspect files in an isolated environment to observe their behavior safely
  4. D.creating a bit-for-bit forensic copy of storage to preserve evidence integrity

Answer + AI explanation with Pro

23. Which term means: "executing suspect files in an isolated environment to observe their behavior safely"?

Mid
  1. A.Sandboxing
  2. B.Rootkit
  3. C.Trojan
  4. D.Timeline analysis

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Sandboxing — pattern-matching rules that identify and classify malware by textual or binary signatures
  2. B.Sandboxing — analyzing RAM captures to find running malware, injected code, and artifacts
  3. C.Sandboxing — executing suspect files in an isolated environment to observe their behavior safely
  4. D.Sandboxing — malware or device that records keystrokes to capture credentials and data

Answer + AI explanation with Pro

25. What is Disk imaging?

Senior
  1. A.creating a bit-for-bit forensic copy of storage to preserve evidence integrity
  2. B.self-replicating malware that spreads across networks without user interaction
  3. C.malware or device that records keystrokes to capture credentials and data
  4. D.reconstructing the sequence of events from filesystem and log timestamps during an investigation

Answer + AI explanation with Pro

26. Which term means: "creating a bit-for-bit forensic copy of storage to preserve evidence integrity"?

Senior
  1. A.Polymorphic malware
  2. B.Disk imaging
  3. C.Sandboxing
  4. D.Timeline analysis

Answer + AI explanation with Pro

27. Which statement is correct?

Senior
  1. A.Disk imaging — creating a bit-for-bit forensic copy of storage to preserve evidence integrity
  2. B.Disk imaging — executing suspect files in an isolated environment to observe their behavior safely
  3. C.Disk imaging — pattern-matching rules that identify and classify malware by textual or binary signatures
  4. D.Disk imaging — malicious code that runs in memory using legitimate tools, leaving little on disk

Answer + AI explanation with Pro

28. What is YARA rules?

Senior
  1. A.reconstructing the sequence of events from filesystem and log timestamps during an investigation
  2. B.self-replicating malware that spreads across networks without user interaction
  3. C.pattern-matching rules that identify and classify malware by textual or binary signatures
  4. D.stealthy malware that hides its presence and grants persistent privileged access

Answer + AI explanation with Pro

29. Which term means: "pattern-matching rules that identify and classify malware by textual or binary signatures"?

Senior
  1. A.YARA rules
  2. B.Disk imaging
  3. C.Timeline analysis
  4. D.Fileless malware

Answer + AI explanation with Pro

30. Which statement is correct?

Senior
  1. A.YARA rules — malware that attaches to a host file and spreads when that file is executed
  2. B.YARA rules — pattern-matching rules that identify and classify malware by textual or binary signatures
  3. C.YARA rules — malware disguised as legitimate software to trick users into running it
  4. D.YARA rules — malware or device that records keystrokes to capture credentials and data

Answer + AI explanation with Pro

Showing 30 of 54 Malware & Forensics questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Malware & Forensics question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers