CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is conducting a forensic investigation after a suspected intrusion. The analyst needs to collect volatile data from a compromised server. Which of the following data types should be collected FIRST due to its highly ephemeral nature?

  1. AHard drive contents
  2. BSystem logs (e.g., event logs)
  3. CRegistry hives
  4. DRunning processes and open network connections
Show answer & explanation

Correct answer: D. Running processes and open network connections

The order of volatility dictates that data that changes most rapidly and is lost when a system is powered off or rebooted should be collected first. Running processes and open network connections reside in RAM and are highly volatile, making them a top priority over disk-based data like logs, registry, or full disk images.

Why the other options are wrong

  • A. Hard drive contents are non-volatile and can be collected later via imaging.
  • B. System logs are typically stored on disk and are less volatile than RAM contents, though still important to collect.
  • C. Registry hives are stored on disk and are non-volatile, making them a lower priority for immediate collection.

Order of Volatility

A principle in digital forensics that dictates the sequence in which different types of evidence should be collected, starting with the most volatile (ephemeral) data.

  • Data in RAM is more volatile than data on disk.
  • Prevents loss of critical evidence that might disappear quickly.
  • Common order: CPU cache, RAM, network state, running processes, disk, logs, archival media.

Memory trick: Volatile data 'Vanish' quickly, so collect it first!

More Security Operations questions