nerdexam
EC-Council

212-89 · Question #106

Marley was asked by his incident handling and response (IH&R) team lead to collect volatile data such as system information and network information present in the registries, cache, and RAM of…

The correct answer is C. Live data acquisition. Live data acquisition is the process of collecting volatile data from a system that is still running. Volatile data includes information stored in system memory (RAM), cache, and system and network configuration settings that are lost when the system is powered off. This method…

Computer Forensics in Incident Handling

Question

Marley was asked by his incident handling and response (IH&R) team lead to collect volatile data such as system information and network information present in the registries, cache, and RAM of victim's system. Identify the data acquisition method Marley must employ to collect volatile data.

Options

  • AValidate data acquisition
  • BStatic data acquisition
  • CLive data acquisition
  • DRemote data acquisition

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    88% (46)
  • D
    2% (1)

Explanation

Live data acquisition is the process of collecting volatile data from a system that is still running. Volatile data includes information stored in system memory (RAM), cache, and system and network configuration settings that are lost when the system is powered off. This method is essential for capturing data that can provide insights into the state of the system at the time of an incident, including active network connections, running processes, and the contents of memory. Marley must employ live data acquisition to ensure that this crucial and ephemeral data is not lost, which can be pivotal in understanding and responding to the incident effectively.

Topics

#live data acquisition#volatile data#RAM forensics#data collection methods

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice