SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy

During a security incident, a forensic investigator needs to collect volatile data from a compromised server. Which of the following data types should be collected FIRST due to its ephemeral nature?

  1. AHard drive contents
  2. BRegistry hives
  3. CSystem logs
  4. DNetwork connections (open sockets)
Show answer & explanation

Correct answer: D. Network connections (open sockets)

Volatile data is information that is lost when a system is powered down or loses power. Network connections (open sockets) are among the most volatile data types, as they represent active communication sessions that would be immediately lost upon system shutdown or network interruption. Therefore, they should be collected first.

Why the other options are wrong

  • A. Hard drive contents are persistent data and not volatile.
  • B. Registry hives are persistent data stored on disk, though parts of the registry are loaded into volatile memory.
  • C. System logs are typically persistent, stored on disk, and less volatile than active memory or network connections.

Volatile Data Forensics

Data that exists only in a system's running memory (RAM) or active state and is lost when the system is powered off or rebooted. It must be collected early in a forensic investigation.

  • Lost on power loss/reboot.
  • Includes RAM, CPU registers, network connections, process tables.
  • Crucial for understanding live system state.
  • Collected in a specific order of volatility.

Memory trick: Faster the fade, sooner the grab.

More Security Operations and Administration questions