MCQ Collection
Semester Exam MCQs
Semester Exam preparation MCQs for university and college students. This section includes subject-wise practice questions, answers, and explanations to help learners prepare for midterm exams, final exams, quizzes, and academic tests.
Choose an option to check your answer.
A.
Isolated environment used to safely observe suspicious files or activity.
B.
Evidence destruction chamber.
C.
Production server.
D.
Public website.
Show Answer
Correct Answer: A. Isolated environment used to safely observe suspicious files or activity.
Explanation:
Sandbox use refers to isolated environment used to safely observe suspicious files or activity.
Choose an option to check your answer.
A.
To support preparedness building during an investigation.
B.
To perform evidence hiding without authorization.
C.
To replace all legal documentation.
D.
To avoid evidence documentation.
Show Answer
Correct Answer: A. To support preparedness building during an investigation.
Explanation:
The purpose of education and awareness is connected with preparedness building, not with altering or avoiding evidence procedures.
Choose an option to check your answer.
A.
That content may have been accessed or loaded
B.
That the user wrote the website code
C.
That the computer is physically damaged
D.
That encryption was broken
Show Answer
Correct Answer: A. That content may have been accessed or loaded
Explanation:
Cache artifacts can support conclusions about web activity.
Choose an option to check your answer.
A.
To support controlled analysis environment during an investigation.
B.
To perform evidence destruction chamber without authorization.
C.
To replace all legal documentation.
D.
To avoid evidence documentation.
Show Answer
Correct Answer: A. To support controlled analysis environment during an investigation.
Explanation:
The purpose of sandbox use is connected with controlled analysis environment, not with altering or avoiding evidence procedures.
Choose an option to check your answer.
A.
Document the process and preserve evidence integrity.
B.
Modify original evidence to make analysis easier.
C.
Ignore chain of custody because the case is technical.
D.
Delete unrelated files from the original device.
Show Answer
Correct Answer: A. Document the process and preserve evidence integrity.
Explanation:
Forensic work requires documentation and preservation of evidence integrity, especially when handling education and awareness.
Choose an option to check your answer.
A.
Application artifact
B.
Physical fingerprint
C.
Optical label
D.
Network cable
Show Answer
Correct Answer: A. Application artifact
Explanation:
Local app databases are common application artifacts.
Choose an option to check your answer.
A.
Document the process and preserve evidence integrity.
B.
Modify original evidence to make analysis easier.
C.
Ignore chain of custody because the case is technical.
D.
Delete unrelated files from the original device.
Show Answer
Correct Answer: A. Document the process and preserve evidence integrity.
Explanation:
Forensic work requires documentation and preservation of evidence integrity, especially when handling sandbox use.
Choose an option to check your answer.
A.
A plan defining logging, roles, evidence handling, and response preparation.
B.
After-incident guessing.
C.
Malware deployment.
D.
Unauthorized access.
Show Answer
Correct Answer: A. A plan defining logging, roles, evidence handling, and response preparation.
Explanation:
Digital forensic readiness plan refers to a plan defining logging, roles, evidence handling, and response preparation.
Choose an option to check your answer.
A.
Anti-forensics
B.
Forensic readiness
C.
Evidence preservation
D.
Timeline analysis
Show Answer
Correct Answer: A. Anti-forensics
Explanation:
Wiping is used to hinder recovery and is an anti-forensic technique.
Choose an option to check your answer.
A.
Using virtual machines to isolate analysis and reproduce environments.
B.
Evidence editing.
C.
Cable testing.
D.
File printing.
Show Answer
Correct Answer: A. Using virtual machines to isolate analysis and reproduce environments.
Explanation:
Virtualization in forensics refers to using virtual machines to isolate analysis and reproduce environments.
Choose an option to check your answer.
A.
To support pre-incident planning during an investigation.
B.
To perform after-incident guessing without authorization.
C.
To replace all legal documentation.
D.
To avoid evidence documentation.
Show Answer
Correct Answer: A. To support pre-incident planning during an investigation.
Explanation:
The purpose of digital forensic readiness plan is connected with pre-incident planning, not with altering or avoiding evidence procedures.
Choose an option to check your answer.
A.
Repeatability
B.
Randomness
C.
Volatility
D.
Obfuscation
Show Answer
Correct Answer: A. Repeatability
Explanation:
Repeatable results improve confidence in tool output.