CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
During a forensic investigation, a security analyst needs to acquire volatile data from a compromised Windows server before powering it down for a full disk image. The server is still running, and the analyst has administrative access. Which of the following data types should the analyst prioritize collecting first due to its highly volatile nature?
- ADisk MFT (Master File Table)
- BSystem logs (Event Viewer)
- CRunning processes and open network connections
- DRegistry hives
Show answer & explanationAnswer & explanation
Correct answer: C. Running processes and open network connections
Running processes and open network connections reside in RAM and are lost immediately upon system shutdown or reboot. This makes them the most volatile data type among the options provided and thus the highest priority for collection.
Why the other options are wrong
- A. The MFT is a critical file system structure stored on disk and is persistent.
- B. System logs are stored on disk and are less volatile than RAM-resident data.
- D. Registry hives are stored on disk, although parts may be cached in memory.
Order of Volatility
A principle in digital forensics that dictates the sequence in which different types of evidence should be collected, starting with the most volatile (easily lost) and ending with the most persistent.
- Data in RAM is highly volatile.
- Network state is highly volatile.
- Disk data is generally persistent.
Memory trick: Really Nasty Cache Files Always Disk Drive