CompTIA CySA+ (CS0-003)Incident Response and ManagementHard
A security analyst is dispatched to a remote office to investigate a suspected malware infection on a critical workstation. The analyst arrives and finds the workstation powered off. To preserve the most volatile evidence, what should the analyst do FIRST?
- APower on the system and immediately collect a RAM dump.
- BRemove the hard drive and create a forensic image of it on-site.
- CDisconnect the network cable and then power on the system.
- DDo NOT power on the system; transport it to the forensic lab.
Show answer & explanationAnswer & explanation
Correct answer: D. Do NOT power on the system; transport it to the forensic lab.
If a system is already powered off, volatile data (like RAM contents) is already lost. Powering it on would alter the system state, potentially overwriting existing evidence on the disk or activating persistence mechanisms. The best practice is to transport the system as-is to a forensic lab for controlled analysis, preserving the disk state.
Why the other options are wrong
- A. Powering on the system would destroy any remaining subtle volatile evidence (e.g., in hibernation files) and alter the disk state, which is not ideal.
- B. Removing the hard drive on-site can be risky and may invalidate warranties or cause damage. Transporting the whole system allows for more controlled acquisition in a lab environment.
- C. Disconnecting the network is good, but powering on still alters the system significantly. The primary volatile data (RAM) is already gone.
Powered-Off System Forensics
The forensic approach for collecting evidence from a system that is found in a powered-off state.
- Volatile data is already lost.
- Priority is preserving persistent storage (disk).
- Avoid powering on to prevent alteration.
Memory trick: Live is RAM, Dead is Disk: Don't 'Wake the Dead' if you want disk integrity.