CompTIA Security+ (SY0-701)Security OperationsEasy

A security analyst is investigating a suspected malware infection on a critical server. Before performing any remediation actions, the analyst needs to ensure that all volatile data is captured in a specific order to preserve evidence. Which of the following data types should the analyst prioritize capturing FIRST?

  1. ACPU cache and registers
  2. BHard drive contents
  3. CSystem memory (RAM) dump
  4. DNetwork connection states
Show answer & explanation

Correct answer: A. CPU cache and registers

In digital forensics, the order of volatility dictates that the most volatile data should be collected first, as it is most likely to be lost or overwritten. CPU cache and registers are the most volatile, followed by RAM, then network states, and finally persistent storage like hard drives.

Why the other options are wrong

  • B. Hard drive contents are persistent and less volatile than memory or CPU data, so they should be captured later.
  • C. System memory (RAM) is volatile but less so than CPU cache and registers; it should be captured after CPU data.
  • D. Network connection states are volatile but generally persist longer than CPU cache or RAM data in a live system.

Order of Volatility

The sequence in which digital evidence should be collected during a forensic investigation, from most volatile (easily lost) to least volatile (persistent).

  • Ensures critical evidence is not lost.
  • Prioritizes data based on its lifespan.
  • Varies by system state and data type.

Memory trick: Remember 'Live Free or Die' for data volatility: Live (CPU), Free (RAM), or (Network), Die (Disk).

More Security Operations questions