CompTIA Security+ (SY0-701)Security OperationsHard
A security analyst is conducting a forensic investigation after a suspected intrusion. The analyst needs to preserve volatile data from a compromised Linux server before shutting it down for a full disk image. Which of the following should be collected FIRST?
- AMemory (RAM) contents
- BSystem logs from disk
- CNetwork connection information
- DHard drive contents
Show answer & explanationAnswer & explanation
Correct answer: A. Memory (RAM) contents
Memory (RAM) contents are the most volatile data and will be lost immediately upon system shutdown or power loss. Following the order of volatility, RAM should always be collected before less volatile data like disk contents or even system logs, which are typically written to disk.
Why the other options are wrong
- B. System logs are usually written to disk and are less volatile than RAM, so they can be collected later.
- C. Network connection information is stored in RAM and is part of the volatile data that would be lost if RAM isn't collected first.
- D. Hard drive contents are non-volatile and can be imaged after more volatile data is collected.
Order of Volatility
A principle in digital forensics that dictates the sequence in which data should be collected, starting with the most volatile data that is most likely to be lost.
- RAM is most volatile
- Disk data is less volatile
- Ensures critical evidence is not lost
Memory trick: Fastest to vanish, first to grab.