312-49 · Question #480
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
The correct answer is A. True. This statement is True. Volatile information - such as running processes, active network connections, logged-in users, clipboard contents, and RAM contents - exists only while the system is powered on and is lost upon shutdown or reboot. Despite (or because of) its transient…
Question
Volatile information can be easily modified or lost when the system is shut down or rebooted. It helps to determine a logical timeline of the security incident and the users who would be responsible.
Options
- ATrue
- BFalse
How the community answered
(29 responses)- A93% (27)
- B7% (2)
Explanation
This statement is True. Volatile information - such as running processes, active network connections, logged-in users, clipboard contents, and RAM contents - exists only while the system is powered on and is lost upon shutdown or reboot. Despite (or because of) its transient nature, it is extremely valuable in digital forensics: it can reveal active attacker sessions, malicious processes, encryption keys in memory, and help construct a timeline of events. Forensic investigators must collect volatile data first, before any other action that might alter system state.
Topics
Community Discussion
No community discussion yet for this question.