CompTIA Security+ (SY0-701)Security OperationsHard
A forensic investigator is collecting evidence from a compromised server that must remain powered on for business continuity. Following the order of volatility, which data source should be collected FIRST?
- AData stored on the hard disk drive
- BArchived log files on backup tape
- CData stored in an offsite cloud backup
- DContents of RAM and running processes
Show answer & explanationAnswer & explanation
Correct answer: D. Contents of RAM and running processes
The order of volatility dictates that the most volatile data—CPU registers, cache, and RAM (including running processes and network connections)—must be collected first because it is lost when the system loses power or state changes, whereas disk, backups, and archives are far less volatile and can be collected later.
Why the other options are wrong
- A. Disk data is less volatile than RAM and can be imaged after memory capture.
- B. Archived backup tapes are the least volatile and can wait until last.
- C. Offsite cloud backups are stable and not time-sensitive like memory data.
Order of Volatility
A forensic principle dictating the sequence for collecting evidence, starting with the most volatile (likely to change or disappear) data first.
- Order: CPU registers/cache > RAM > swap/paging > disk > logs > archival media
- RAM captures running processes, network connections, encryption keys
- Volatile data lost on reboot/power-off
- Guides evidence collection priority during live forensics
Memory trick: Grab the ghost (RAM) before it vanishes.