SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy

A security incident response team is conducting a forensic analysis of a compromised workstation. They need to collect volatile data quickly before the system is powered off or rebooted. Which of the following data types should be prioritized for collection due to its highly volatile nature?

  1. ARegistry files
  2. BEvent logs
  3. CHard drive contents
  4. DSystem memory (RAM)
Show answer & explanation

Correct answer: D. System memory (RAM)

System memory (RAM) is the most volatile data type among the options provided. Its contents are lost immediately when the system is powered off or rebooted, making it a top priority for collection in live forensic investigations.

Why the other options are wrong

  • A. Registry files are persistent data stored on the hard drive.
  • B. Event logs are typically stored on persistent storage (hard drive) and remain after a reboot, though recent entries might not be synced immediately.
  • C. Hard drive contents are persistent data and are not lost on power off.

Volatile Data Forensics

Volatile data in forensics refers to information that is present in a computer's memory or running processes and will be lost when the system is powered down or rebooted. Its collection is critical for live incident response.

  • Lost upon system shutdown/reboot.
  • Includes RAM contents, running processes, network connections, logged-on users.
  • Collected first in live forensic investigations.
  • Provides insights into current system state and attacker activity.

Memory trick: Memory fades fast, so grab it first!

More Security Operations and Administration questions