ISC2 Certified in Cybersecurity (CC)Security OperationsHard

A forensic investigator is examining a compromised server. They need to collect volatile data first to ensure no critical evidence is lost before the system is powered down for a full disk image. Which of the following data types would the investigator prioritize collecting immediately?

  1. AMemory (RAM) contents
  2. BRegistry files from persistent storage
  3. CApplication configuration files
  4. DSystem logs from the hard drive
Show answer & explanation

Correct answer: A. Memory (RAM) contents

Volatile data is information that is lost when a system loses power or is shut down. Memory (RAM) contents are highly volatile and contain crucial runtime information that would be lost if not collected first.

Why the other options are wrong

  • B. Registry files are stored persistently on the hard drive.
  • C. Application configuration files are persistent data stored on the hard drive.
  • D. System logs on the hard drive are persistent data and will remain after shutdown.

Volatile Data

Information that exists in a temporary state and is lost when a computer system is powered down or loses power, such as RAM contents, CPU registers, and network connections.

  • Must be collected first in forensics
  • Includes active processes, open network connections, RAM data
  • Contrasts with persistent data (e.g., hard drive contents)

Memory trick: Volatile data vanishes like smoke, collect it fast!

More Security Operations questions