Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive company data. The analyst needs to collect forensic evidence from the employee's workstation, prioritizing data that is most likely to be lost when the system is powered off. Which type of data should the analyst focus on collecting first?

  1. ARegistry files
  2. BSystem memory (RAM) dump
  3. CEvent logs
  4. DHard drive contents (disk image)
Show answer & explanation

Correct answer: B. System memory (RAM) dump

Volatile data, such as system memory (RAM) contents, is lost when a system is powered off or rebooted. In forensic investigations, it is crucial to collect the most volatile data first to preserve evidence that might otherwise disappear. Hard drive contents, registry files, and event logs are persistent and can be collected later.

Why the other options are wrong

  • A. Registry files are stored on the hard drive and are persistent.
  • C. Event logs are stored on the hard drive and are persistent, though they can be overwritten.
  • D. Hard drive contents are persistent and can be collected after volatile data.

Volatile Data Forensics

Volatile data in forensics refers to information that exists only in the computer's memory (RAM), CPU caches, or network state and is lost when the system loses power or is shut down. It must be collected early in an investigation.

  • Lost on system shutdown.
  • Crucial for live forensics.
  • Includes RAM, running processes, network connections.

Memory trick: RAM is Gone, Disk Stays On.

More Security Operations questions