Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard

A SOC analyst is investigating a potential data exfiltration incident. During the analysis phase, they need to gather evidence from a compromised workstation without altering its state. Which of the following forensic techniques is most appropriate for preserving the integrity of volatile data on the system?

  1. ADumping RAM (Random Access Memory) before powering down the system.
  2. BAnalyzing static log files stored on a remote SIEM.
  3. CCollecting network traffic captures from the perimeter firewall.
  4. DPerforming a full disk image while the system is powered off.
Show answer & explanation

Correct answer: A. Dumping RAM (Random Access Memory) before powering down the system.

Volatile data, such as RAM contents, is lost when a system is powered off. To preserve this crucial evidence, a memory dump must be performed while the system is still running. This captures active processes, network connections, and other in-memory artifacts that would otherwise be destroyed, which is essential for preserving the integrity of volatile data.

Why the other options are wrong

  • B. Analyzing remote log files is important but doesn't capture volatile data directly from the compromised system.
  • C. Network traffic captures are external to the workstation and do not preserve its internal volatile state.
  • D. Full disk imaging is for non-volatile data and powering off destroys volatile data.

Volatile Data Forensics

The process of collecting data from a live system that will be lost once the system is powered off or rebooted.

  • Includes RAM, CPU registers, network connections, and running processes.
  • Must be collected in a specific order of volatility (least volatile last).
  • Crucial for understanding attacker activity on a live system.

Memory trick: Volatile data is like a ghost, gone if you turn off the lights.

More Security Operations questions