CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

During an incident response, a security analyst needs to perform deep forensic analysis on a compromised Windows server. The server is still running and critical for business operations, so it cannot be immediately shut down. Which of the following artifact types should the analyst prioritize collecting first due to its high volatility?

  1. ANetwork configuration (ipconfig /all)
  2. BDisk image
  3. CMemory (RAM) dump
  4. DSystem logs (Event Viewer)
Show answer & explanation

Correct answer: C. Memory (RAM) dump

Memory (RAM) is the most volatile data source on a live system, containing active processes, network connections, and cryptographic keys that are lost immediately upon shutdown or system crash. Prioritizing its collection ensures this critical evidence is not lost.

Why the other options are wrong

  • A. Network configuration, while useful, is also persistent or easily re-collected and less volatile than RAM contents.
  • B. A disk image captures persistent storage and is less volatile than RAM.
  • D. System logs are persistent on disk and less volatile than RAM.

Order of Volatility

The order in which digital evidence should be collected, from most volatile (data easily lost) to least volatile (data that persists), to ensure critical evidence is preserved.

  • RAM is typically the most volatile.
  • Network state, running processes, and open files are also highly volatile.
  • Disk data is the least volatile.
  • Collection order minimizes data loss.

Memory trick: Remember RAM first, then network, then disk, like a rapid breath.

More Incident Response and Management questions