CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is investigating a suspected insider threat. The analyst needs to collect volatile data from a running Windows server without altering the system state unnecessarily. Which of the following data types should be collected FIRST due to its ephemeral nature?

  1. AHard drive contents (full disk image)
  2. BSystem memory (RAM dump)
  3. CNetwork traffic captures (PCAPs)
  4. DRegistry hives and configuration files
Show answer & explanation

Correct answer: B. System memory (RAM dump)

System memory (RAM) is the most volatile data and contains crucial information about running processes, network connections, and open files that would be lost immediately if the system were shut down or rebooted. Therefore, it should be collected first.

Why the other options are wrong

  • A. Hard drive contents are persistent and can be imaged later, after volatile data is secured.
  • C. Network traffic captures are important, but active RAM contents provide a snapshot of the system's internal state at a specific moment, which is more volatile than ongoing network traffic that can be recorded over time.
  • D. Registry hives and configuration files are persistent data stored on the hard drive and are not as volatile as RAM.

Order of Volatility

A hierarchy of digital evidence based on how quickly it can be lost or altered, guiding collection priorities.

  • Most volatile data collected first.
  • RAM is typically the most volatile.
  • Disk data is less volatile than RAM.

Memory trick: R-C-N-D: RAM, Cache, Network, Disk. Get the 'Airy' data first!

More Incident Response and Management questions