Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard
A SOC analyst is investigating a potential data exfiltration incident. During the analysis phase, they need to gather evidence from a compromised workstation without altering its state. Which of the following forensic techniques is most appropriate for preserving the integrity of volatile data on the system?
- ADumping RAM (Random Access Memory) before powering down the system.
- BAnalyzing static log files stored on a remote SIEM.
- CCollecting network traffic captures from the perimeter firewall.
- DPerforming a full disk image while the system is powered off.
Show answer & explanationAnswer & explanation
Correct answer: A. Dumping RAM (Random Access Memory) before powering down the system.
Volatile data, such as RAM contents, is lost when a system is powered off. To preserve this crucial evidence, a memory dump must be performed while the system is still running. This captures active processes, network connections, and other in-memory artifacts that would otherwise be destroyed, which is essential for preserving the integrity of volatile data.
Why the other options are wrong
- B. Analyzing remote log files is important but doesn't capture volatile data directly from the compromised system.
- C. Network traffic captures are external to the workstation and do not preserve its internal volatile state.
- D. Full disk imaging is for non-volatile data and powering off destroys volatile data.
Volatile Data Forensics
The process of collecting data from a live system that will be lost once the system is powered off or rebooted.
- Includes RAM, CPU registers, network connections, and running processes.
- Must be collected in a specific order of volatility (least volatile last).
- Crucial for understanding attacker activity on a live system.
Memory trick: Volatile data is like a ghost, gone if you turn off the lights.