CompTIA Security+ (SY0-701)Security OperationsMedium
A security analyst is conducting a forensic investigation after a suspected intrusion. The analyst needs to collect volatile data from a compromised server. Which of the following data types should be collected FIRST due to its highly ephemeral nature?
- AHard drive contents
- BSystem logs (e.g., event logs)
- CRegistry hives
- DRunning processes and open network connections
Show answer & explanationAnswer & explanation
Correct answer: D. Running processes and open network connections
The order of volatility dictates that data that changes most rapidly and is lost when a system is powered off or rebooted should be collected first. Running processes and open network connections reside in RAM and are highly volatile, making them a top priority over disk-based data like logs, registry, or full disk images.
Why the other options are wrong
- A. Hard drive contents are non-volatile and can be collected later via imaging.
- B. System logs are typically stored on disk and are less volatile than RAM contents, though still important to collect.
- C. Registry hives are stored on disk and are non-volatile, making them a lower priority for immediate collection.
Order of Volatility
A principle in digital forensics that dictates the sequence in which different types of evidence should be collected, starting with the most volatile (ephemeral) data.
- Data in RAM is more volatile than data on disk.
- Prevents loss of critical evidence that might disappear quickly.
- Common order: CPU cache, RAM, network state, running processes, disk, logs, archival media.
Memory trick: Volatile data 'Vanish' quickly, so collect it first!